HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2016-0778

CVSS 8.1v3.0pub. 2016-01-14upd. 2026-05-29

The (1) roaming_read and (2) roaming_write functions in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2, when certain proxy and forward options are enabled, do not properly maintain connection file descriptors, which allows remote servers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact by requesting many forwardings.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Apple Mac Os X

    OS
    Apple
    10.11.0 – 10.11.310.9.0 – 10.9.510.10.0 – 10.10.5
  • HP Virtual Customer Access System

    OS
    Hp
    ≤ 15.07
  • Openbsd OpenSSH

    APP
    Openbsd
    5.45.55.65.75.85.96.06.16.26.36.46.56.66.76.8+ 3 more
  • Oracle Linux

    OS
    Oracle
    7
  • Oracle Solaris

    OS
    Oracle
    11.3
  • Sophos Unified Threat Management Software

    APP
    Sophos
    9.353
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
DoSMemory
CWE
References

Related vulnerabilities

CVE-2021-1870CRITICAL9.8⚠ KEVPL ✓same product

Zdalne wykonanie kodu (RCE) w Apple iOS, iPadOS i macOS

CVE-2021-1871CRITICAL9.8⚠ KEVPL ✓same product

Zdalne wykonanie kodu przez błąd logiczny w systemach Apple (RCE)

CVE-2020-14871CRITICAL10.0⚠ KEVPL ✓same product

Oracle Solaris PAM — zdalne przejęcie systemu bez uwierzytelnienia

CVE-2016-4171CRITICAL9.8⚠ KEVPL ✓same product

RCE w Adobe Flash Player 21.0.0.242 i wcześniejszych — aktywnie exploitowany

CVE-2016-3427CRITICAL9.8⚠ KEVPL ✓same product

Krytyczna podatność RCE w Oracle Java SE i JRockit — komponent JMX