ZeroHour

CVE-2016-0777

CVSS 3.1
6.5 medium
EPSS
63%p99
Published
()
Modified
Description

The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitive information from process memory by requesting transmission of an entire buffer, as demonstrated by reading a private key.

Vendors
sophosoracleopenbsdhpapple
Products
unified threat management software, linux, solaris, openssh, remote device access virtual customer access system, mac os x
Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.