The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitive information from process memory by requesting transmission of an entire buffer, as demonstrated by reading a private key.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NApple Mac Os X
OSApple≤ 10.11.3HP Remote Device Access Virtual Customer Access System
APPHp≤ 15.07Openbsd OpenSSH
APPOpenbsd5.05.15.25.35.45.55.65.75.85.96.06.16.26.36.4+ 7 moreOracle Linux
OSOracle7Oracle Solaris
OSOracle11.3Sophos Unified Threat Management
HWSophos110120220320425525625Sophos Unified Threat Management Software
APPSophos9.3189.353
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
References
Related vulnerabilities
CVE-2021-1871CRITICAL9.8⚠ KEVPL ✓same product
Zdalne wykonanie kodu przez błąd logiczny w systemach Apple (RCE)
CVE-2021-1870CRITICAL9.8⚠ KEVPL ✓same product
Zdalne wykonanie kodu (RCE) w Apple iOS, iPadOS i macOS
CVE-2020-14871CRITICAL10.0⚠ KEVPL ✓same product
Oracle Solaris PAM — zdalne przejęcie systemu bez uwierzytelnienia
CVE-2020-25223CRITICAL9.8⚠ KEVPL ✓same product
RCE w Sophos SG UTM WebAdmin — command injection bez uwierzytelnienia
CVE-2016-4171CRITICAL9.8⚠ KEVPL ✓same product
RCE w Adobe Flash Player 21.0.0.242 i wcześniejszych — aktywnie exploitowany