ISOMAN

CVE

CVE-2016-0777

The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitive information from process memory by requesting transmission of an entire buffer, as demonstrated by reading a private key.

Severity
MEDIUM
CVSS
6.5
Published
Modified

Linked Releases

References

  1. http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10734
  2. http://lists.apple.com/archives/security-announce/2016/Mar/msg00004.html
  3. http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176516.html
  4. http://lists.fedoraproject.org/pipermail/package-announce/2016-January/175592.html
  5. http://lists.fedoraproject.org/pipermail/package-announce/2016-January/175676.html
  6. http://lists.fedoraproject.org/pipermail/package-announce/2016-January/176349.html
  7. http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00006.html
  8. http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00007.html
  9. http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00008.html
  10. http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00009.html
  11. http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00013.html
  12. http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00014.html
  13. http://packetstormsecurity.com/files/135273/Qualys-Security-Advisory-OpenSSH-Overflow-Leak.html
  14. http://seclists.org/fulldisclosure/2016/Jan/44
  15. http://www.debian.org/security/2016/dsa-3446
  16. http://www.openssh.com/txt/release-7.1p2
  17. http://www.openwall.com/lists/oss-security/2016/01/14/7
  18. http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html
  19. http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
  20. http://www.securityfocus.com/archive/1/537295/100/0/threaded