Red Hat Bugzilla – Bug 208349
CVE-2006-5052 GSSAPI information leak
Last modified: 2007-11-30 17:07:34 EST
OpenSSH 4.4 was released and mentions:
* On portable OpenSSH, fix a GSSAPI authentication abort that
could be used to determine the validity of usernames on some
This could only affect RHEL4 as previous RHEL did not support GSSAPI
(We currently don't know if this would affect Linux)
openssh-3.9p1 is not vulnerable to this abort - but see #234643.
This flaw does affect RHEL5 is seems. I'm reopening this bug against RHEL5.
*** This bug has been marked as a duplicate of 234643 ***