CVE-2007-2768

EPSS 0.19%
Published: 5/21/2007Modified: 4/28/2026

Description

OpenSSH, when using OPIE (One-Time Passwords in Everything) for PAM, allows remote attackers to determine the existence of certain user accounts, which displays a different response if the user account exists and is configured to use one-time passwords (OTP), a similar issue to CVE-2007-2243.

Affected packages (1)

References (1)