[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2016-0778Date: (C)2016-02-11   (M)2024-02-01


The (1) roaming_read and (2) roaming_write functions in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2, when certain proxy and forward options are enabled, do not properly maintain connection file descriptors, which allows remote servers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact by requesting many forwardings.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 8.1CVSS Score : 4.6
Exploit Score: 2.2Exploit Score: 3.9
Impact Score: 5.9Impact Score: 6.4
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: NETWORKAccess Vector: NETWORK
Attack Complexity: HIGHAccess Complexity: HIGH
Privileges Required: NONEAuthentication: SINGLE
User Interaction: NONEConfidentiality: PARTIAL
Scope: UNCHANGEDIntegrity: PARTIAL
Confidentiality: HIGHAvailability: PARTIAL
Integrity: HIGH 
Availability: HIGH 
  
Reference:
SECTRACK-1034671
http://www.securityfocus.com/archive/1/537295/100/0/threaded
http://seclists.org/fulldisclosure/2016/Jan/44
BID-80698
APPLE-SA-2016-03-21-5
DSA-3446
FEDORA-2016-2e89eba0c1
FEDORA-2016-4556904561
GLSA-201601-01
SUSE-SU-2016:0117
SUSE-SU-2016:0118
SUSE-SU-2016:0119
SUSE-SU-2016:0120
USN-2869-1
http://www.openwall.com/lists/oss-security/2016/01/14/7
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10734
http://packetstormsecurity.com/files/135273/Qualys-Security-Advisory-OpenSSH-Overflow-Leak.html
http://www.openssh.com/txt/release-7.1p2
http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html
http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
https://blogs.sophos.com/2016/02/17/utm-up2date-9-354-released/
https://blogs.sophos.com/2016/02/29/utm-up2date-9-319-released/
https://bto.bluecoat.com/security-advisory/sa109
https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05247375
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05356388
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05385680
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722
https://support.apple.com/HT206167
openSUSE-SU-2016:0127
openSUSE-SU-2016:0128

CWE    1
CWE-119
OVAL    16
oval:org.secpod.oval:def:602337
oval:org.secpod.oval:def:1600390
oval:org.secpod.oval:def:110118
oval:org.secpod.oval:def:110088
...

© SecPod Technologies