ZeroHour

CVE-2016-10708

CVSS 3.1
7.5 high
EPSS
16%p97
Published
()
Modified
Description

sshd in OpenSSH before 7.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence NEWKEYS message, as demonstrated by Honggfuzz, related to kex.c and packet.c.

Vendors
openbsddebiancanonicalnetapp
Products
openssh, debian linux, ubuntu linux, cloud backup, data ontap, data ontap edge, oncommand unified manager, service processor, storagegrid, storagegrid webscale, clustered data ontap, vasa provider
Weakness
CWE-476
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.