CVE-2016-0777

medium HPE
CVSS v3 Base Score
6.5
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score
67.2%
Exploitation probability in 30 days
Top 1% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Confidentiality
High
Integrity
None
Availability
None
Published: January 14, 2016 (3773 days ago)
Last Modified: May 6, 2026
Vendor: HPE
Source: NVD

Description

The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitive information from process memory by requesting transmission of an entire buffer, as demonstrated by reading a private key.

CWE

CWE-200

Affected Products

sophos unified threat management softwareoracle linuxoracle solarisopenbsd opensshhp remote device access virtual customer access systemapple mac os x

References