The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitive information from process memory by requesting transmission of an entire buffer, as demonstrated by reading a private key.
2016-01-14T22:59:01.140
2025-04-12T10:46:40.837
Deferred
CVSSv3.0: 6.5 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:N/A:N
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | sophos | unified_threat_management_software | 9.318 | Yes |
Application | sophos | unified_threat_management_software | 9.353 | Yes |
Hardware | sophos | unified_threat_management | 110 | No |
Hardware | sophos | unified_threat_management | 120 | No |
Hardware | sophos | unified_threat_management | 220 | No |
Hardware | sophos | unified_threat_management | 320 | No |
Hardware | sophos | unified_threat_management | 425 | No |
Hardware | sophos | unified_threat_management | 525 | No |
Hardware | sophos | unified_threat_management | 625 | No |
Operating System | oracle | linux | 7 | Yes |
Operating System | oracle | solaris | 11.3 | Yes |
Application | openbsd | openssh | 5.0 | Yes |
Application | openbsd | openssh | 5.0 | Yes |
Application | openbsd | openssh | 5.1 | Yes |
Application | openbsd | openssh | 5.1 | Yes |
Application | openbsd | openssh | 5.2 | Yes |
Application | openbsd | openssh | 5.2 | Yes |
Application | openbsd | openssh | 5.3 | Yes |
Application | openbsd | openssh | 5.3 | Yes |
Application | openbsd | openssh | 5.4 | Yes |
Application | openbsd | openssh | 5.4 | Yes |
Application | openbsd | openssh | 5.5 | Yes |
Application | openbsd | openssh | 5.5 | Yes |
Application | openbsd | openssh | 5.6 | Yes |
Application | openbsd | openssh | 5.6 | Yes |
Application | openbsd | openssh | 5.7 | Yes |
Application | openbsd | openssh | 5.7 | Yes |
Application | openbsd | openssh | 5.8 | Yes |
Application | openbsd | openssh | 5.8 | Yes |
Application | openbsd | openssh | 5.9 | Yes |
Application | openbsd | openssh | 5.9 | Yes |
Application | openbsd | openssh | 6.0 | Yes |
Application | openbsd | openssh | 6.0 | Yes |
Application | openbsd | openssh | 6.1 | Yes |
Application | openbsd | openssh | 6.1 | Yes |
Application | openbsd | openssh | 6.2 | Yes |
Application | openbsd | openssh | 6.2 | Yes |
Application | openbsd | openssh | 6.2 | Yes |
Application | openbsd | openssh | 6.3 | Yes |
Application | openbsd | openssh | 6.3 | Yes |
Application | openbsd | openssh | 6.4 | Yes |
Application | openbsd | openssh | 6.4 | Yes |
Application | openbsd | openssh | 6.5 | Yes |
Application | openbsd | openssh | 6.5 | Yes |
Application | openbsd | openssh | 6.6 | Yes |
Application | openbsd | openssh | 6.6 | Yes |
Application | openbsd | openssh | 6.7 | Yes |
Application | openbsd | openssh | 6.7 | Yes |
Application | openbsd | openssh | 6.8 | Yes |
Application | openbsd | openssh | 6.8 | Yes |
Application | openbsd | openssh | 6.9 | Yes |
Application | openbsd | openssh | 6.9 | Yes |
Application | openbsd | openssh | 7.0 | Yes |
Application | openbsd | openssh | 7.0 | Yes |
Application | openbsd | openssh | 7.1 | Yes |
Application | openbsd | openssh | 7.1 | Yes |
Application | hp | remote_device_access_virtual_customer_access_system | ≤ 15.07 | Yes |
Operating System | apple | mac_os_x | ≤ 10.11.3 | Yes |