CVE-2016-0777
medium · 6.5The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitive information from process memory by requesting transmission of an entire buffer, as demonstrated by reading a private key.
6.5
CVSS
63.5%
EPSS (exploit prob.)
99th
EPSS percentile
2016-01-14
Published
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weaknesses
CWE-200
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| sophos | unified_threat_management_software | 9.318 |
| sophos | unified_threat_management_software | 9.353 |
| sophos | unified_threat_management | 110 |
| sophos | unified_threat_management | 120 |
| sophos | unified_threat_management | 220 |
| sophos | unified_threat_management | 320 |
| sophos | unified_threat_management | 425 |
| sophos | unified_threat_management | 525 |
| sophos | unified_threat_management | 625 |
| oracle | linux | 7 |
| oracle | solaris | 11.3 |
| openbsd | openssh | 5.0 |
| openbsd | openssh | 5.0 |
| openbsd | openssh | 5.1 |
| openbsd | openssh | 5.1 |
| openbsd | openssh | 5.2 |
| openbsd | openssh | 5.2 |
| openbsd | openssh | 5.3 |
| openbsd | openssh | 5.3 |
| openbsd | openssh | 5.4 |
| openbsd | openssh | 5.4 |
| openbsd | openssh | 5.5 |
| openbsd | openssh | 5.5 |
| openbsd | openssh | 5.6 |
| openbsd | openssh | 5.6 |
| openbsd | openssh | 5.7 |
| openbsd | openssh | 5.7 |
| openbsd | openssh | 5.8 |
| openbsd | openssh | 5.8 |
| openbsd | openssh | 5.9 |
| openbsd | openssh | 5.9 |
| openbsd | openssh | 6.0 |
| openbsd | openssh | 6.0 |
| openbsd | openssh | 6.1 |
| openbsd | openssh | 6.1 |
| openbsd | openssh | 6.2 |
| openbsd | openssh | 6.2 |
| openbsd | openssh | 6.2 |
| openbsd | openssh | 6.3 |
| openbsd | openssh | 6.3 |
Check a specific version with /api/v1/cve/match.
References
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10734
- http://lists.apple.com/archives/security-announce/2016/Mar/msg00004.html
- http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176516.html
- http://lists.fedoraproject.org/pipermail/package-announce/2016-January/175592.html
- http://lists.fedoraproject.org/pipermail/package-announce/2016-January/175676.html
- http://lists.fedoraproject.org/pipermail/package-announce/2016-January/176349.html
- http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00006.html
- http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00007.html
- http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00008.html
- http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00009.html
- http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00013.html
- http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00014.html
- http://packetstormsecurity.com/files/135273/Qualys-Security-Advisory-OpenSSH-Overflow-Leak.html
- http://seclists.org/fulldisclosure/2016/Jan/44
- http://www.debian.org/security/2016/dsa-3446
- http://www.openssh.com/txt/release-7.1p2
- http://www.openwall.com/lists/oss-security/2016/01/14/7
- http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
- http://www.securityfocus.com/archive/1/537295/100/0/threaded
- http://www.securityfocus.com/bid/80695
- http://www.securitytracker.com/id/1034671
- http://www.ubuntu.com/usn/USN-2869-1
- https://blogs.sophos.com/2016/02/17/utm-up2date-9-354-released/
- https://blogs.sophos.com/2016/02/29/utm-up2date-9-319-released/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2016-0777