{"id":"CVE-2007-2768","details":"OpenSSH, when using OPIE (One-Time Passwords in Everything) for PAM, allows remote attackers to determine the existence of certain user accounts, which displays a different response if the user account exists and is configured to use one-time passwords (OTP), a similar issue to CVE-2007-2243.","modified":"2026-04-10T03:38:53.814260Z","published":"2007-05-21T20:30:00Z","references":[{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20191107-0002/"},{"type":"WEB","url":"http://archives.neohapsis.com/archives/fulldisclosure/2007-04/0635.html"},{"type":"WEB","url":"http://www.osvdb.org/34601"}],"schema_version":"1.7.5"}