Dropbear SSH server timing attacks
Description:Different timings for existent and nonexistent users.
CVE:CVE-2013-4434 (Dropbear SSH Server before 2013.59 generates error messages for a failed logon attempt with different time delays depending on whether the user account exists, which allows remote attackers to discover valid usernames.)
 CVE-2013-4421 (The buf_decompress function in packet.c in Dropbear SSH Server before 2013.59 allows remote attackers to cause a denial of service (memory consumption) via a compressed packet that has a large size when it is decompressed.)
Original documentdocumentMANDRIVA, [ MDVSA-2013:261 ] dropbear (05.11.2013)

