cbcvebase.
CVE-2016-0777
published 2016-01-14

CVE-2016-0777: The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitive information…

PriorityP352medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
63.47%
99.1th percentile
The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitive information from process memory by requesting transmission of an entire buffer, as demonstrated by reading a private key.

Affected

35 ranges· showing 25
VendorProductVersion rangeFixed in
applemac_os_x<= 10.11.3
appleos_x_el_capitan_v10.11.4_and_security_update_2016-002
debianopenssh< openssh 1:7.1p2-1 (bookworm)openssh 1:7.1p2-1 (bookworm)
hpremote_device_access_virtual_customer_access_system<= 15.07
openbsdopenssh
openbsdopenssh
openbsdopenssh
openbsdopenssh
openbsdopenssh
openbsdopenssh
openbsdopenssh
openbsdopenssh
openbsdopenssh
openbsdopenssh
openbsdopenssh
openbsdopenssh
openbsdopenssh
openbsdopenssh
openbsdopenssh
openbsdopenssh
openbsdopenssh
openbsdopenssh
openbsdopenssh
openbsdopenssh
openbsdopenssh

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerable roaming feature in OpenSSH client can be detected by monitoring for the stderr message printed when a roaming reconnection is triggered
  • Affected code is in roaming_common.c — the resend_bytes function is the specific vulnerable function to target in source-level or binary analysis
  • Affected OpenSSH versions are 5.x, 6.x, and 7.x before 7.1p2; version fingerprinting of SSH banners can identify vulnerable clients
  • ·The vulnerable roaming code can be permanently disabled by adding 'UseRoaming no' to the system-wide SSH client configuration file, per-user config, or via command-line flag; absence of this setting on affected versions indicates exposure
  • ·Red Hat Enterprise Linux 4, 5, and 6 ship OpenSSH versions not affected by this CVE; RHEL 7 is affected only in a non-default configuration
  • ·Non-interactive SSH commands (e.g., backup scripts and cron jobs) using public-key authentication are particularly high-risk targets for exploitation of this leak
  • ·Debian fixed this vulnerability in package version 1:7.1p2-1 across all tracked releases

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.