Description: Andrea Purificato has reported a vulnerability in HP Tru64, which can be exploited by malicious people to gain knowledge of system information.
The problem is that it is possible to determine whether a user exists on a system or not by measuring the time it takes before a reply is received when connecting to the ssh service with an arbitrary user name.
The vulnerability affects the following versions:
* HP Tru64 UNIX v5.1B-4
* HP Tru64 UNIX v5.1B-3
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.