Lucene search

K
archlinuxArch LinuxASA-201601-9
HistoryJan 14, 2016 - 12:00 a.m.

openssh: multiple issues

2016-01-1400:00:00
Arch Linux
lists.archlinux.org
26

0.003 Low

EPSS

Percentile

67.8%

  • CVE-2016-0777 (information disclosure)

An information leak flaw was found in the way the OpenSSH client roaming
feature was implemented. A malicious server could potentially use this
flaw to leak portions of memory (possibly including private SSH keys) of
a successfully authenticated OpenSSH client.

  • CVE-2016-0778 (arbitrary code execution)

A buffer overflow flaw was found in the way the OpenSSH client roaming
feature was implemented that is leading to a file descriptor leak. A
malicious server could potentially use this flaw to execute arbitrary
code on a successfully authenticated OpenSSH client if that client used
certain non-default configuration options (ProxyCommand, ForwardAgent or
ForwardX11).

OSVersionArchitecturePackageVersionFilename
anyanyanyopenssh< 7.1p2-1UNKNOWN