MEDIUM✓ PATCH🇵🇱 Wersja polska

CVE-2016-0777

CVSS 6.5v3.0pub. 2016-01-14upd. 2026-05-29

The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitive information from process memory by requesting transmission of an entire buffer, as demonstrated by reading a private key.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
  • Apple Mac Os X

    OS
    Apple
    ≤ 10.11.3
  • HP Remote Device Access Virtual Customer Access System

    APP
    Hp
    ≤ 15.07
  • Openbsd OpenSSH

    APP
    Openbsd
    5.05.15.25.35.45.55.65.75.85.96.06.16.26.36.4+ 7 more
  • Oracle Linux

    OS
    Oracle
    7
  • Oracle Solaris

    OS
    Oracle
    11.3
  • Sophos Unified Threat Management

    HW
    Sophos
    110120220320425525625
  • Sophos Unified Threat Management Software

    APP
    Sophos
    9.3189.353
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2021-1871CRITICAL9.8⚠ KEVPL ✓same product

Zdalne wykonanie kodu przez błąd logiczny w systemach Apple (RCE)

CVE-2021-1870CRITICAL9.8⚠ KEVPL ✓same product

Zdalne wykonanie kodu (RCE) w Apple iOS, iPadOS i macOS

CVE-2020-14871CRITICAL10.0⚠ KEVPL ✓same product

Oracle Solaris PAM — zdalne przejęcie systemu bez uwierzytelnienia

CVE-2020-25223CRITICAL9.8⚠ KEVPL ✓same product

RCE w Sophos SG UTM WebAdmin — command injection bez uwierzytelnienia

CVE-2016-4171CRITICAL9.8⚠ KEVPL ✓same product

RCE w Adobe Flash Player 21.0.0.242 i wcześniejszych — aktywnie exploitowany