Bug#827429: openssh in jessie might leak info regarding validity of usernames

2016-06-16 Thread Mattia Rizzolo
control: reassign -1 openssh-server 6.7p1-5+deb8u2 [ please don't keep me in the recipients while discussing the bug ] On Wed, Jun 15, 2016 at 10:55:12PM -0400, Raouf M. Bencheraiet wrote: > Package: opernssh-server typoed name :) > Version: 6.7p1-5+deb8u2 > > When trying to connect to a host

Bug#827429: openssh in jessie might leak info regarding validity of usernames

2016-06-15 Thread Raouf M. Bencheraiet
Package: opernssh-server Version: 6.7p1-5+deb8u2 When trying to connect to a host with an invalid username and that and the "too many authentication failures" is hit, the hosts leaks whether the username is valid or not. for ex: ssh badusr@X.X.X.X Received disconnect from X.X.X.X port 22:2: