The (1) roaming_read and (2) roaming_write functions in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2, when certain proxy and forward options are enabled, do not properly maintain connection file descriptors, which allows remote servers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact by requesting many forwardings.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HApple Mac Os X
OSApple10.11.0 – 10.11.310.9.0 – 10.9.510.10.0 – 10.10.5HP Virtual Customer Access System
OSHp≤ 15.07Openbsd OpenSSH
APPOpenbsd5.45.55.65.75.85.96.06.16.26.36.46.56.66.76.8+ 3 moreOracle Linux
OSOracle7Oracle Solaris
OSOracle11.3Sophos Unified Threat Management Software
APPSophos9.353
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
DoSMemory
References
Related vulnerabilities
CVE-2021-1870CRITICAL9.8⚠ KEVPL ✓same product
Zdalne wykonanie kodu (RCE) w Apple iOS, iPadOS i macOS
CVE-2021-1871CRITICAL9.8⚠ KEVPL ✓same product
Zdalne wykonanie kodu przez błąd logiczny w systemach Apple (RCE)
CVE-2020-14871CRITICAL10.0⚠ KEVPL ✓same product
Oracle Solaris PAM — zdalne przejęcie systemu bez uwierzytelnienia
CVE-2016-4171CRITICAL9.8⚠ KEVPL ✓same product
RCE w Adobe Flash Player 21.0.0.242 i wcześniejszych — aktywnie exploitowany
CVE-2016-3427CRITICAL9.8⚠ KEVPL ✓same product
Krytyczna podatność RCE w Oracle Java SE i JRockit — komponent JMX