The (1) roaming_read and (2) roaming_write functions in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2, when certain proxy and forward options are enabled, do not properly maintain connection file descriptors, which allows remote servers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact by requesting many forwardings.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HApple Mac Os X
OSApple10.11.0 – 10.11.310.9.0 – 10.9.510.10.0 – 10.10.5HP Virtual Customer Access System
OSHp≤ 15.07Openbsd OpenSSH
APPOpenbsd5.45.55.65.75.85.96.06.16.26.36.46.56.66.76.8+ 3 więcejOracle Linux
OSOracle7Oracle Solaris
OSOracle11.3Sophos Unified Threat Management Software
APPSophos9.353
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
Tagi
DoSMemory
Referencje
Powiązane podatności
CVE-2021-1870CRITICAL9.8⚠ KEVPL ✓ten sam produkt
Zdalne wykonanie kodu (RCE) w Apple iOS, iPadOS i macOS
CVE-2021-1871CRITICAL9.8⚠ KEVPL ✓ten sam produkt
Zdalne wykonanie kodu przez błąd logiczny w systemach Apple (RCE)
CVE-2020-14871CRITICAL10.0⚠ KEVPL ✓ten sam produkt
Oracle Solaris PAM — zdalne przejęcie systemu bez uwierzytelnienia
CVE-2016-4171CRITICAL9.8⚠ KEVPL ✓ten sam produkt
RCE w Adobe Flash Player 21.0.0.242 i wcześniejszych — aktywnie exploitowany
CVE-2016-3427CRITICAL9.8⚠ KEVPL ✓ten sam produkt
Krytyczna podatność RCE w Oracle Java SE i JRockit — komponent JMX