← All CVEs

CVE-2016-0778

high · 8.1

The (1) roaming_read and (2) roaming_write functions in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2, when certain proxy and forward options are enabled, do not properly maintain connection file descriptors, which allows remote servers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact by requesting many forwardings.

8.1
CVSS
20.9%
EPSS (exploit prob.)
97th
EPSS percentile
2016-01-14
Published

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
oraclelinux7
oraclesolaris11.3
openbsdopenssh5.4
openbsdopenssh5.4
openbsdopenssh5.5
openbsdopenssh5.5
openbsdopenssh5.6
openbsdopenssh5.6
openbsdopenssh5.7
openbsdopenssh5.7
openbsdopenssh5.8
openbsdopenssh5.8
openbsdopenssh5.9
openbsdopenssh5.9
openbsdopenssh6.0
openbsdopenssh6.0
openbsdopenssh6.1
openbsdopenssh6.1
openbsdopenssh6.2
openbsdopenssh6.2
openbsdopenssh6.2
openbsdopenssh6.3
openbsdopenssh6.3
openbsdopenssh6.4
openbsdopenssh6.4
openbsdopenssh6.5
openbsdopenssh6.5
openbsdopenssh6.6
openbsdopenssh6.6
openbsdopenssh6.7
openbsdopenssh6.7
openbsdopenssh6.8
openbsdopenssh6.8
openbsdopenssh6.9
openbsdopenssh6.9
openbsdopenssh7.0
openbsdopenssh7.0
openbsdopenssh7.1
openbsdopenssh7.1
applemac_os_x>= 10.9.0, <= 10.9.5

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2016-0778