CVE-2016-0777
Vulnerability Summary
Timeline
Description
The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitive information from process memory by requesting transmission of an entire buffer, as demonstrated by reading a private key.
CVSS Metrics
- v3.1•MEDIUM•Score: 6.5CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- v3.0•MEDIUM•Score: 6.5CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- v2.0•MEDIUM•Score: 4AV:N/AC:L/Au:S/C:P/I:N/A:N
EPSS Trends
Current EPSS score: 71.66%• Percentile: 99%
Techniques & Countermeasures
- CWE-200•Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Affected Systems
- apple•mac_os_x
≤ 10.11.3
- hp•remote_device_access_virtual_customer_access_system
≤ 15.07
- openbsd•openssh
5.0 | 5.0:p1 | 5.1 | 5.1:p1 | 5.2 | 5.2:p1 | 5.3 | 5.3:p1 | 5.4 | 5.4:p1 | 5.5 | 5.5:p1 | 5.6 | 5.6:p1 | 5.7 | 5.7:p1 | 5.8 | 5.8:p1 | 5.9 | 5.9:p1 | 6.0 | 6.0:p1 | 6.1 | 6.1:p1 | 6.2 | 6.2:p1 | 6.2:p2 | 6.3 | 6.3:p1 | 6.4 | 6.4:p1 | 6.5 | 6.5:p1 | 6.6 | 6.6:p1 | 6.7 | 6.7:p1 | 6.8 | 6.8:p1 | 6.9 | 6.9:p1 | 7.0 | 7.0:p1 | 7.1 | 7.1:p1
- oracle•linux
7
- Unknown•Solaris
11.3
- sophos•unified_threat_management_software
9.318 | 9.353
References (34)
- https://blogs.sophos.com/2016/02/17/utm-up2date-9-354-released/
- http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00006.html
- https://blogs.sophos.com/2016/02/29/utm-up2date-9-319-released/
- http://lists.apple.com/archives/security-announce/2016/Mar/msg00004.html
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05247375
- http://www.securityfocus.com/archive/1/537295/100/0/threaded
- https://support.apple.com/HT206167
- http://lists.fedoraproject.org/pipermail/package-announce/2016-January/176349.html
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10734
- http://www.securityfocus.com/bid/80695
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05385680
- https://security.FreeBSD.org/advisories/FreeBSD-SA-16:07.openssh.asc
- http://lists.fedoraproject.org/pipermail/package-announce/2016-January/175676.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
- http://www.openssh.com/txt/release-7.1p2
- http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00014.html
- http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176516.html
- https://bto.bluecoat.com/security-advisory/sa109
- http://www.securitytracker.com/id/1034671
- http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00013.html
- https://security.gentoo.org/glsa/201601-01
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722
- http://www.openwall.com/lists/oss-security/2016/01/14/7
- http://seclists.org/fulldisclosure/2016/Jan/44
- http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00008.html
- http://packetstormsecurity.com/files/135273/Qualys-Security-Advisory-OpenSSH-Overflow-Leak.html
- http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00007.html
- http://lists.fedoraproject.org/pipermail/package-announce/2016-January/175592.html
- http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00009.html
- http://www.ubuntu.com/usn/USN-2869-1
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05356388
- http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html
- http://www.debian.org/security/2016/dsa-3446
- https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf