sshd in OpenSSH before 7.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence NEWKEYS message, as demonstrated by Honggfuzz, related to kex.c and packet.c.
2018-01-21T22:29:00.227
2024-11-21T02:44:33.607
Modified
CVSSv3.0: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | openbsd | openssh | < 7.4 | Yes |
| Operating System | debian | debian_linux | 7.0 | Yes |
| Operating System | debian | debian_linux | 8.0 | Yes |
| Operating System | canonical | ubuntu_linux | 14.04 | Yes |
| Operating System | canonical | ubuntu_linux | 16.04 | Yes |
| Operating System | canonical | ubuntu_linux | 18.04 | Yes |
| Application | netapp | cloud_backup | - | Yes |
| Application | netapp | data_ontap | - | Yes |
| Application | netapp | data_ontap_edge | - | Yes |
| Application | netapp | oncommand_unified_manager | ≥ 9.4 | Yes |
| Application | netapp | service_processor | - | Yes |
| Application | netapp | storagegrid | - | Yes |
| Application | netapp | storagegrid_webscale | - | Yes |
| Operating System | netapp | clustered_data_ontap | - | Yes |
| Application | netapp | vasa_provider | - | Yes |
| Operating System | netapp | clustered_data_ontap | - | No |