Ubuntu 4.10 : openssh information leakage (USN-34-1)

@Mediaservice.net discovered two information leaks in the OpenSSH
server. When using password authentication, an attacker could test
whether a login name exists by measuring the time between failed login
attempts, i. e. the time after which the 'password:' prompt appears

A similar issue affects systems which do not allow root logins over
ssh ('PermitRootLogin no'). By measuring the time between login
attempts an attacker could check whether a given root password is
correct. This allowed determining weak root passwords using a brute
force attack.

CVE ID: CVE-2003-0190