---
title: "CVE-2006-5229\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2006-5229?format=md
keywords: index, follow
---

# CVE-2006-5229

Publication date 10 October 2006

Last updated 17 July 2025

---

Ubuntu priority

**Negligible**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

OpenSSH portable 4.1 on SUSE Linux, and possibly other platforms and
versions, and possibly under limited configurations, allows remote
attackers to determine valid usernames via timing discrepancies in which
responses take longer for valid usernames than invalid ones, as
demonstrated by sshtime. NOTE: as of 20061014, it appears that this issue
is dependent on the use of manually-set passwords that causes delays when
processing /etc/shadow due to an increased number of rounds.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2006-5229?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| openssh | 7.04 feisty | Ignored |
| 6.10 edgy | Ignored |
| 6.06 LTS dapper | Ignored |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [kees](https://launchpad.net/~kees)

up to administrators to resolve module usage

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5229)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2006-5229)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2006-5229)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2006-5229)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2006-5229>
