CVE-2016-0777
MEDIUM severity · CVSS 6.5 · Information disclosure
6.5CVSS MEDIUM
Summary
The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitive information from process memory by requesting transmission of an entire buffer, as demonstrated by reading a private key.
Impact & exploitability
Attack vectorNetwork
Attack complexityLow
Privileges requiredLow
User interactionNone
Confidentiality impactHigh
Integrity impactNone
Availability impactNone
Exploit probability (EPSS)63%
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Additional information
- NVD record
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10734Advisory
- http://lists.apple.com/archives/security-announce/2016/Mar/msg00004.htmlAdvisory
- http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176516.htmlAdvisory
- http://lists.fedoraproject.org/pipermail/package-announce/2016-January/175592.htmlAdvisory
- http://lists.fedoraproject.org/pipermail/package-announce/2016-January/175676.htmlAdvisory
- http://lists.fedoraproject.org/pipermail/package-announce/2016-January/176349.htmlAdvisory
- http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00006.htmlAdvisory
- http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00007.htmlAdvisory