// For flags

CVE-2016-0777

OpenSSH: Client Information leak due to use of roaming connection feature

Severity Score

6.5
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitive information from process memory by requesting transmission of an entire buffer, as demonstrated by reading a private key.

La función resend_bytes en roaming_common.c en el cliente en OpenSSH 5.x, 6.x y 7.x en versiones anteriores a 7.1p2 permite a servidores remotos obtener información sensible desde la memoria de proceso mediante la petición de transmisión de un buffer completo, según lo demostrado mediante la lectura de una clave privada.

An information leak flaw was found in the way the OpenSSH client roaming feature was implemented. A malicious server could potentially use this flaw to leak portions of memory (possibly including private SSH keys) of a successfully authenticated OpenSSH client.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Partial
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2015-12-16 CVE Reserved
  • 2016-01-14 CVE Published
  • 2024-08-05 CVE Updated
  • 2024-08-12 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
  • CWE-682: Incorrect Calculation
CAPEC
References (37)
URL Tag Source
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10734 Third Party Advisory
http://packetstormsecurity.com/files/135273/Qualys-Security-Advisory-OpenSSH-Overflow-Leak.html Third Party Advisory
http://seclists.org/fulldisclosure/2016/Jan/44 Mailing List
http://www.openwall.com/lists/oss-security/2016/01/14/7 Mailing List
http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html Third Party Advisory
http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html Third Party Advisory
http://www.securityfocus.com/archive/1/537295/100/0/threaded Mailing List
http://www.securityfocus.com/bid/80695 Third Party Advisory
http://www.securitytracker.com/id/1034671 Third Party Advisory
https://blogs.sophos.com/2016/02/17/utm-up2date-9-354-released Third Party Advisory
https://blogs.sophos.com/2016/02/29/utm-up2date-9-319-released Third Party Advisory
https://bto.bluecoat.com/security-advisory/sa109 Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05247375 Third Party Advisory
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05356388 Third Party Advisory
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05385680 Third Party Advisory
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722 Third Party Advisory
https://support.apple.com/HT206167 Third Party Advisory
URL Date SRC
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Sophos
Search vendor "Sophos"
Unified Threat Management Software
Search vendor "Sophos" for product "Unified Threat Management Software"
9.318
Search vendor "Sophos" for product "Unified Threat Management Software" and version "9.318"
-
Affected
in Sophos
Search vendor "Sophos"
Unified Threat Management
Search vendor "Sophos" for product "Unified Threat Management"
110
Search vendor "Sophos" for product "Unified Threat Management" and version "110"
-
Safe
Sophos
Search vendor "Sophos"
Unified Threat Management Software
Search vendor "Sophos" for product "Unified Threat Management Software"
9.318
Search vendor "Sophos" for product "Unified Threat Management Software" and version "9.318"
-
Affected
in Sophos
Search vendor "Sophos"
Unified Threat Management
Search vendor "Sophos" for product "Unified Threat Management"
120
Search vendor "Sophos" for product "Unified Threat Management" and version "120"
-
Safe
Sophos
Search vendor "Sophos"
Unified Threat Management Software
Search vendor "Sophos" for product "Unified Threat Management Software"
9.318
Search vendor "Sophos" for product "Unified Threat Management Software" and version "9.318"
-
Affected
in Sophos
Search vendor "Sophos"
Unified Threat Management
Search vendor "Sophos" for product "Unified Threat Management"
220
Search vendor "Sophos" for product "Unified Threat Management" and version "220"
-
Safe
Sophos
Search vendor "Sophos"
Unified Threat Management Software
Search vendor "Sophos" for product "Unified Threat Management Software"
9.318
Search vendor "Sophos" for product "Unified Threat Management Software" and version "9.318"
-
Affected
in Sophos
Search vendor "Sophos"
Unified Threat Management
Search vendor "Sophos" for product "Unified Threat Management"
320
Search vendor "Sophos" for product "Unified Threat Management" and version "320"
-
Safe
Sophos
Search vendor "Sophos"
Unified Threat Management Software
Search vendor "Sophos" for product "Unified Threat Management Software"
9.318
Search vendor "Sophos" for product "Unified Threat Management Software" and version "9.318"
-
Affected
in Sophos
Search vendor "Sophos"
Unified Threat Management
Search vendor "Sophos" for product "Unified Threat Management"
425
Search vendor "Sophos" for product "Unified Threat Management" and version "425"
-
Safe
Sophos
Search vendor "Sophos"
Unified Threat Management Software
Search vendor "Sophos" for product "Unified Threat Management Software"
9.318
Search vendor "Sophos" for product "Unified Threat Management Software" and version "9.318"
-
Affected
in Sophos
Search vendor "Sophos"
Unified Threat Management
Search vendor "Sophos" for product "Unified Threat Management"
525
Search vendor "Sophos" for product "Unified Threat Management" and version "525"
-
Safe
Sophos
Search vendor "Sophos"
Unified Threat Management Software
Search vendor "Sophos" for product "Unified Threat Management Software"
9.318
Search vendor "Sophos" for product "Unified Threat Management Software" and version "9.318"
-
Affected
in Sophos
Search vendor "Sophos"
Unified Threat Management
Search vendor "Sophos" for product "Unified Threat Management"
625
Search vendor "Sophos" for product "Unified Threat Management" and version "625"
-
Safe
Sophos
Search vendor "Sophos"
Unified Threat Management Software
Search vendor "Sophos" for product "Unified Threat Management Software"
9.353
Search vendor "Sophos" for product "Unified Threat Management Software" and version "9.353"
-
Affected
in Sophos
Search vendor "Sophos"
Unified Threat Management
Search vendor "Sophos" for product "Unified Threat Management"
110
Search vendor "Sophos" for product "Unified Threat Management" and version "110"
-
Safe
Sophos
Search vendor "Sophos"
Unified Threat Management Software
Search vendor "Sophos" for product "Unified Threat Management Software"
9.353
Search vendor "Sophos" for product "Unified Threat Management Software" and version "9.353"
-
Affected
in Sophos
Search vendor "Sophos"
Unified Threat Management
Search vendor "Sophos" for product "Unified Threat Management"
120
Search vendor "Sophos" for product "Unified Threat Management" and version "120"
-
Safe
Sophos
Search vendor "Sophos"
Unified Threat Management Software
Search vendor "Sophos" for product "Unified Threat Management Software"
9.353
Search vendor "Sophos" for product "Unified Threat Management Software" and version "9.353"
-
Affected
in Sophos
Search vendor "Sophos"
Unified Threat Management
Search vendor "Sophos" for product "Unified Threat Management"
220
Search vendor "Sophos" for product "Unified Threat Management" and version "220"
-
Safe
Sophos
Search vendor "Sophos"
Unified Threat Management Software
Search vendor "Sophos" for product "Unified Threat Management Software"
9.353
Search vendor "Sophos" for product "Unified Threat Management Software" and version "9.353"
-
Affected
in Sophos
Search vendor "Sophos"
Unified Threat Management
Search vendor "Sophos" for product "Unified Threat Management"
320
Search vendor "Sophos" for product "Unified Threat Management" and version "320"
-
Safe
Sophos
Search vendor "Sophos"
Unified Threat Management Software
Search vendor "Sophos" for product "Unified Threat Management Software"
9.353
Search vendor "Sophos" for product "Unified Threat Management Software" and version "9.353"
-
Affected
in Sophos
Search vendor "Sophos"
Unified Threat Management
Search vendor "Sophos" for product "Unified Threat Management"
425
Search vendor "Sophos" for product "Unified Threat Management" and version "425"
-
Safe
Sophos
Search vendor "Sophos"
Unified Threat Management Software
Search vendor "Sophos" for product "Unified Threat Management Software"
9.353
Search vendor "Sophos" for product "Unified Threat Management Software" and version "9.353"
-
Affected
in Sophos
Search vendor "Sophos"
Unified Threat Management
Search vendor "Sophos" for product "Unified Threat Management"
525
Search vendor "Sophos" for product "Unified Threat Management" and version "525"
-
Safe
Sophos
Search vendor "Sophos"
Unified Threat Management Software
Search vendor "Sophos" for product "Unified Threat Management Software"
9.353
Search vendor "Sophos" for product "Unified Threat Management Software" and version "9.353"
-
Affected
in Sophos
Search vendor "Sophos"
Unified Threat Management
Search vendor "Sophos" for product "Unified Threat Management"
625
Search vendor "Sophos" for product "Unified Threat Management" and version "625"
-
Safe
Oracle
Search vendor "Oracle"
Linux
Search vendor "Oracle" for product "Linux"
7
Search vendor "Oracle" for product "Linux" and version "7"
-
Affected
Oracle
Search vendor "Oracle"
Solaris
Search vendor "Oracle" for product "Solaris"
11.3
Search vendor "Oracle" for product "Solaris" and version "11.3"
-
Affected
Openbsd
Search vendor "Openbsd"
Openssh
Search vendor "Openbsd" for product "Openssh"
5.0
Search vendor "Openbsd" for product "Openssh" and version "5.0"
-
Affected
Openbsd
Search vendor "Openbsd"
Openssh
Search vendor "Openbsd" for product "Openssh"
5.0
Search vendor "Openbsd" for product "Openssh" and version "5.0"
p1
Affected
Openbsd
Search vendor "Openbsd"
Openssh
Search vendor "Openbsd" for product "Openssh"
5.1
Search vendor "Openbsd" for product "Openssh" and version "5.1"
-
Affected
Openbsd
Search vendor "Openbsd"
Openssh
Search vendor "Openbsd" for product "Openssh"
5.1
Search vendor "Openbsd" for product "Openssh" and version "5.1"
p1
Affected
Openbsd
Search vendor "Openbsd"
Openssh
Search vendor "Openbsd" for product "Openssh"
5.2
Search vendor "Openbsd" for product "Openssh" and version "5.2"
-
Affected
Openbsd
Search vendor "Openbsd"
Openssh
Search vendor "Openbsd" for product "Openssh"
5.2
Search vendor "Openbsd" for product "Openssh" and version "5.2"
p1
Affected
Openbsd
Search vendor "Openbsd"
Openssh
Search vendor "Openbsd" for product "Openssh"
5.3
Search vendor "Openbsd" for product "Openssh" and version "5.3"
-
Affected
Openbsd
Search vendor "Openbsd"
Openssh
Search vendor "Openbsd" for product "Openssh"
5.3
Search vendor "Openbsd" for product "Openssh" and version "5.3"
p1
Affected
Openbsd
Search vendor "Openbsd"
Openssh
Search vendor "Openbsd" for product "Openssh"
5.4
Search vendor "Openbsd" for product "Openssh" and version "5.4"
-
Affected
Openbsd
Search vendor "Openbsd"
Openssh
Search vendor "Openbsd" for product "Openssh"
5.4
Search vendor "Openbsd" for product "Openssh" and version "5.4"
p1
Affected
Openbsd
Search vendor "Openbsd"
Openssh
Search vendor "Openbsd" for product "Openssh"
5.5
Search vendor "Openbsd" for product "Openssh" and version "5.5"
-
Affected
Openbsd
Search vendor "Openbsd"
Openssh
Search vendor "Openbsd" for product "Openssh"
5.5
Search vendor "Openbsd" for product "Openssh" and version "5.5"
p1
Affected
Openbsd
Search vendor "Openbsd"
Openssh
Search vendor "Openbsd" for product "Openssh"
5.6
Search vendor "Openbsd" for product "Openssh" and version "5.6"
-
Affected
Openbsd
Search vendor "Openbsd"
Openssh
Search vendor "Openbsd" for product "Openssh"
5.6
Search vendor "Openbsd" for product "Openssh" and version "5.6"
p1
Affected
Openbsd
Search vendor "Openbsd"
Openssh
Search vendor "Openbsd" for product "Openssh"
5.7
Search vendor "Openbsd" for product "Openssh" and version "5.7"
-
Affected
Openbsd
Search vendor "Openbsd"
Openssh
Search vendor "Openbsd" for product "Openssh"
5.7
Search vendor "Openbsd" for product "Openssh" and version "5.7"
p1
Affected
Openbsd
Search vendor "Openbsd"
Openssh
Search vendor "Openbsd" for product "Openssh"
5.8
Search vendor "Openbsd" for product "Openssh" and version "5.8"
-
Affected
Openbsd
Search vendor "Openbsd"
Openssh
Search vendor "Openbsd" for product "Openssh"
5.8
Search vendor "Openbsd" for product "Openssh" and version "5.8"
p1
Affected
Openbsd
Search vendor "Openbsd"
Openssh
Search vendor "Openbsd" for product "Openssh"
5.9
Search vendor "Openbsd" for product "Openssh" and version "5.9"
-
Affected
Openbsd
Search vendor "Openbsd"
Openssh
Search vendor "Openbsd" for product "Openssh"
5.9
Search vendor "Openbsd" for product "Openssh" and version "5.9"
p1
Affected
Openbsd
Search vendor "Openbsd"
Openssh
Search vendor "Openbsd" for product "Openssh"
6.0
Search vendor "Openbsd" for product "Openssh" and version "6.0"
-
Affected
Openbsd
Search vendor "Openbsd"
Openssh
Search vendor "Openbsd" for product "Openssh"
6.0
Search vendor "Openbsd" for product "Openssh" and version "6.0"
p1
Affected
Openbsd
Search vendor "Openbsd"
Openssh
Search vendor "Openbsd" for product "Openssh"
6.1
Search vendor "Openbsd" for product "Openssh" and version "6.1"
-
Affected
Openbsd
Search vendor "Openbsd"
Openssh
Search vendor "Openbsd" for product "Openssh"
6.1
Search vendor "Openbsd" for product "Openssh" and version "6.1"
p1
Affected
Openbsd
Search vendor "Openbsd"
Openssh
Search vendor "Openbsd" for product "Openssh"
6.2
Search vendor "Openbsd" for product "Openssh" and version "6.2"
-
Affected
Openbsd
Search vendor "Openbsd"
Openssh
Search vendor "Openbsd" for product "Openssh"
6.2
Search vendor "Openbsd" for product "Openssh" and version "6.2"
p1
Affected
Openbsd
Search vendor "Openbsd"
Openssh
Search vendor "Openbsd" for product "Openssh"
6.2
Search vendor "Openbsd" for product "Openssh" and version "6.2"
p2
Affected
Openbsd
Search vendor "Openbsd"
Openssh
Search vendor "Openbsd" for product "Openssh"
6.3
Search vendor "Openbsd" for product "Openssh" and version "6.3"
-
Affected
Openbsd
Search vendor "Openbsd"
Openssh
Search vendor "Openbsd" for product "Openssh"
6.3
Search vendor "Openbsd" for product "Openssh" and version "6.3"
p1
Affected
Openbsd
Search vendor "Openbsd"
Openssh
Search vendor "Openbsd" for product "Openssh"
6.4
Search vendor "Openbsd" for product "Openssh" and version "6.4"
-
Affected
Openbsd
Search vendor "Openbsd"
Openssh
Search vendor "Openbsd" for product "Openssh"
6.4
Search vendor "Openbsd" for product "Openssh" and version "6.4"
p1
Affected
Openbsd
Search vendor "Openbsd"
Openssh
Search vendor "Openbsd" for product "Openssh"
6.5
Search vendor "Openbsd" for product "Openssh" and version "6.5"
-
Affected
Openbsd
Search vendor "Openbsd"
Openssh
Search vendor "Openbsd" for product "Openssh"
6.5
Search vendor "Openbsd" for product "Openssh" and version "6.5"
p1
Affected
Openbsd
Search vendor "Openbsd"
Openssh
Search vendor "Openbsd" for product "Openssh"
6.6
Search vendor "Openbsd" for product "Openssh" and version "6.6"
-
Affected
Openbsd
Search vendor "Openbsd"
Openssh
Search vendor "Openbsd" for product "Openssh"
6.6
Search vendor "Openbsd" for product "Openssh" and version "6.6"
p1
Affected
Openbsd
Search vendor "Openbsd"
Openssh
Search vendor "Openbsd" for product "Openssh"
6.7
Search vendor "Openbsd" for product "Openssh" and version "6.7"
-
Affected
Openbsd
Search vendor "Openbsd"
Openssh
Search vendor "Openbsd" for product "Openssh"
6.7
Search vendor "Openbsd" for product "Openssh" and version "6.7"
p1
Affected
Openbsd
Search vendor "Openbsd"
Openssh
Search vendor "Openbsd" for product "Openssh"
6.8
Search vendor "Openbsd" for product "Openssh" and version "6.8"
-
Affected
Openbsd
Search vendor "Openbsd"
Openssh
Search vendor "Openbsd" for product "Openssh"
6.8
Search vendor "Openbsd" for product "Openssh" and version "6.8"
p1
Affected
Openbsd
Search vendor "Openbsd"
Openssh
Search vendor "Openbsd" for product "Openssh"
6.9
Search vendor "Openbsd" for product "Openssh" and version "6.9"
-
Affected
Openbsd
Search vendor "Openbsd"
Openssh
Search vendor "Openbsd" for product "Openssh"
6.9
Search vendor "Openbsd" for product "Openssh" and version "6.9"
p1
Affected
Openbsd
Search vendor "Openbsd"
Openssh
Search vendor "Openbsd" for product "Openssh"
7.0
Search vendor "Openbsd" for product "Openssh" and version "7.0"
-
Affected
Openbsd
Search vendor "Openbsd"
Openssh
Search vendor "Openbsd" for product "Openssh"
7.0
Search vendor "Openbsd" for product "Openssh" and version "7.0"
p1
Affected
Openbsd
Search vendor "Openbsd"
Openssh
Search vendor "Openbsd" for product "Openssh"
7.1
Search vendor "Openbsd" for product "Openssh" and version "7.1"
-
Affected
Openbsd
Search vendor "Openbsd"
Openssh
Search vendor "Openbsd" for product "Openssh"
7.1
Search vendor "Openbsd" for product "Openssh" and version "7.1"
p1
Affected
Hp
Search vendor "Hp"
Remote Device Access Virtual Customer Access System
Search vendor "Hp" for product "Remote Device Access Virtual Customer Access System"
<= 15.07
Search vendor "Hp" for product "Remote Device Access Virtual Customer Access System" and version " <= 15.07"
-
Affected
Apple
Search vendor "Apple"
Mac Os X
Search vendor "Apple" for product "Mac Os X"
<= 10.11.3
Search vendor "Apple" for product "Mac Os X" and version " <= 10.11.3"
-
Affected