VDB

DEBIAN-CVE-2007-2768

DEBIAN-CVE-2007-2768 PUBLISHED

OpenSSH, when using OPIE (One-Time Passwords in Everything) for PAM, allows remote attackers to determine the existence of certain user accounts, which displays a different response if the user account exists and is configured to use one-time passwords (OTP), a similar issue to CVE-2007-2243.

Affected Products

VendorProductVersions
Debian:13openssh0, *, *
Debian:12openssh9.7, 9.7, 9.7
Debian:14openssh*, 0, 10.0
Debian:11openssh1:10.2p1-6~bpo13+1, 1:8.4p1-5, 1:8.4p1-5+deb11u1

Timeline

  • May 21, 2007 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›