CVE-2016-0777
published 2016-01-14CVE-2016-0777: The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitive information…
PriorityP352medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
63.47%
99.1th percentile
The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitive information from process memory by requesting transmission of an entire buffer, as demonstrated by reading a private key.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | <= 10.11.3 | — |
| apple | os_x_el_capitan_v10.11.4_and_security_update_2016-002 | — | — |
| debian | openssh | < openssh 1:7.1p2-1 (bookworm) | openssh 1:7.1p2-1 (bookworm) |
| hp | remote_device_access_virtual_customer_access_system | <= 15.07 | — |
| openbsd | openssh | — | — |
| openbsd | openssh | — | — |
| openbsd | openssh | — | — |
| openbsd | openssh | — | — |
| openbsd | openssh | — | — |
| openbsd | openssh | — | — |
| openbsd | openssh | — | — |
| openbsd | openssh | — | — |
| openbsd | openssh | — | — |
| openbsd | openssh | — | — |
| openbsd | openssh | — | — |
| openbsd | openssh | — | — |
| openbsd | openssh | — | — |
| openbsd | openssh | — | — |
| openbsd | openssh | — | — |
| openbsd | openssh | — | — |
| openbsd | openssh | — | — |
| openbsd | openssh | — | — |
| openbsd | openssh | — | — |
| openbsd | openssh | — | — |
| openbsd | openssh | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerable roaming feature in OpenSSH client can be detected by monitoring for the stderr message printed when a roaming reconnection is triggered ↗
- →Affected code is in roaming_common.c — the resend_bytes function is the specific vulnerable function to target in source-level or binary analysis ↗
- →Affected OpenSSH versions are 5.x, 6.x, and 7.x before 7.1p2; version fingerprinting of SSH banners can identify vulnerable clients ↗
- ·The vulnerable roaming code can be permanently disabled by adding 'UseRoaming no' to the system-wide SSH client configuration file, per-user config, or via command-line flag; absence of this setting on affected versions indicates exposure ↗
- ·Red Hat Enterprise Linux 4, 5, and 6 ship OpenSSH versions not affected by this CVE; RHEL 7 is affected only in a non-default configuration ↗
- ·Non-interactive SSH commands (e.g., backup scripts and cron jobs) using public-key authentication are particularly high-risk targets for exploitation of this leak ↗
- ·Debian fixed this vulnerability in package version 1:7.1p2-1 across all tracked releases ↗
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
OpenSSH up to 5.x/6.x/7.1p1 roaming_common.c resend_bytes Memory information disclosure (USN-2869-1 / Nessus ID 87972)
vuldb·2026-05-29·CVSS 6.5
CVE-2016-0777 [MEDIUM] OpenSSH up to 5.x/6.x/7.1p1 roaming_common.c resend_bytes Memory information disclosure (USN-2869-1 / Nessus ID 87972)
A vulnerability has been found in OpenSSH up to 5.x/6.x/7.1p1 and classified as problematic. This impacts the function resend_bytes of the file roaming_common.c. Performing a manipulation results in information disclosure (Memory).
This vulnerability is known as CVE-2016-0777. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.
VulDB
Apple Mac OS X up to 10.11.3 OpenSSH Key information disclosure (HT206167 / Nessus ID 87936)
vuldb·2026-05-29·CVSS 6.5
CVE-2016-0777 [MEDIUM] Apple Mac OS X up to 10.11.3 OpenSSH Key information disclosure (HT206167 / Nessus ID 87936)
A vulnerability described as problematic has been identified in Apple Mac OS X up to 10.11.3. This impacts an unknown function of the component OpenSSH. Such manipulation leads to information disclosure (Key).
This vulnerability is traded as CVE-2016-0777. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.
GHSA
GHSA-9h73-2pqx-3jh8: The resend_bytes function in roaming_common
ghsa_unreviewed·2022-05-13
CVE-2016-0777 [MEDIUM] CWE-200 GHSA-9h73-2pqx-3jh8: The resend_bytes function in roaming_common
The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitive information from process memory by requesting transmission of an entire buffer, as demonstrated by reading a private key.
OSV
CVE-2016-0777: The resend_bytes function in roaming_common
osv·2016-01-14·CVSS 6.5
CVE-2016-0777 [MEDIUM] CVE-2016-0777: The resend_bytes function in roaming_common
The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitive information from process memory by requesting transmission of an entire buffer, as demonstrated by reading a private key.
CISA ICS
Siemens SCALANCE X-200RNA Switch Devices
cisa_ics·2022-12-19
Siemens SCALANCE X-200RNA Switch Devices
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SCALANCE X-200RNA Switch Devices
Last RevisedDecember 19, 2022
Alert CodeICSA-22-349-21
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity/public exploits are available
- Vendor: Siemens
- Equipment: SCALANCE X-200RNA switch devices before V3.2.7
- Vulnerabilities: Observable Timing Discrepancy; Race Condition; Improper Restriction of Operations within the Bounds of a Memory Buffer; Improper Input Validation; NULL Pointer Dereference; Use After Free; Cryptographic Issues; Comparison of Incompatible Types; Resource Management
Red Hat
guile: Thread-unsafe umask modification
vendor_redhat·2016-10-10·CVSS 5.3
CVE-2016-8605 [MEDIUM] guile: Thread-unsafe umask modification
guile: Thread-unsafe umask modification
The mkdir procedure of GNU Guile temporarily changed the process' umask to zero. During that time window, in a multithreaded application, other threads could end up creating files with insecure permissions. For example, mkdir without the optional mode argument would create directories as 0777. This is fixed in Guile 2.0.13. Prior versions are affected.
A vulnerability was found in guile, in the mkdir procedure's usage of umask(2). Under particular circumstances, an attacker could influence an application written in guile to create directories or files insecurely, potentially exposing them to being read or manipulated by local users.
Statement: Red Hat Product Security has rated this issue as having Low security
impact. This issue is not currently
Palo Alto
PAN-SA-2016-0011 OpenSSH vulnerabilities
vendor_paloalto·2016-07-12·CVSS 6.5
CVE-2016-0777 [MEDIUM] CWE-119 PAN-SA-2016-0011 OpenSSH vulnerabilities
PAN-SA-2016-0011 OpenSSH vulnerabilities
OpenSSH contains two vulnerabilities (CVE-2016-0777 and CVE-2016-0778) affecting the SSH client roaming feature when connecting to a malicious server.
CVEs: CVE-2016-0777, CVE-2016-0778
Affected products: PAN-OS
Red Hat
OpenSSH: Client Information leak due to use of roaming connection feature
vendor_redhat·2016-01-14·CVSS 6.5
CVE-2016-0777 [MEDIUM] CWE-682 OpenSSH: Client Information leak due to use of roaming connection feature
OpenSSH: Client Information leak due to use of roaming connection feature
The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitive information from process memory by requesting transmission of an entire buffer, as demonstrated by reading a private key.
An information leak flaw was found in the way the OpenSSH client roaming feature was implemented. A malicious server could potentially use this flaw to leak portions of memory (possibly including private SSH keys) of a successfully authenticated OpenSSH client.
Statement: This issue does not affect the version OpenSSH as shipped with Red Hat Enterprise Linux 4, 5 and 6. This issue affects the version of OpenSSH as shipped with Red Hat Enterprise Linux 7
Ubuntu
OpenSSH vulnerabilities
vendor_ubuntu·2016-01-14
CVE-2016-0777 OpenSSH vulnerabilities
Title: OpenSSH vulnerabilities
Summary: OpenSSH could be made to expose sensitive information over the network.
It was discovered that the OpenSSH client experimental support for resuming
connections contained multiple security issues. A malicious server could
use this issue to leak client memory to the server, including private
client user keys.
Instructions: In general, a standard system update will make all the necessary changes.
BSD
FreeBSD-SA-16:07.openssh: OpenSSH client information leak
bsd_advisories·2016-01-14·CVSS 6.5
CVE-2016-0777 [MEDIUM] FreeBSD-SA-16:07.openssh: OpenSSH client information leak
FreeBSD-SA-16:07.openssh Security Advisory
The FreeBSD Project
Topic: OpenSSH client information leak
Category: contrib
Module: openssh
Announced: 2016-01-14
Credits: Qualys Security Advisory Team
Affects: All supported versions of FreeBSD.
Corrected: 2016-01-14 22:42:43 UTC (stable/10, 10.2-STABLE)
2016-01-14 22:45:33 UTC (releng/10.2, 10.2-RELEASE-p10)
2016-01-14 22:47:54 UTC (releng/10.1, 10.1-RELEASE-p27)
2016-01-14 22:50:35 UTC (stable/9, 9.3-STABLE)
2016-01-14 22:53:07 UTC (releng/9.3, 9.3-RELEASE-p34)
CVE Name: CVE-2016-0777
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Background
OpenSSH is an implementation of the SSH protocol suite, providing an
encry
Debian
CVE-2016-0777: openssh - The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x,...
vendor_debian·2016·CVSS 6.5
CVE-2016-0777 [MEDIUM] CVE-2016-0777: openssh - The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x,...
The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitive information from process memory by requesting transmission of an entire buffer, as demonstrated by reading a private key.
Scope: local
bookworm: resolved (fixed in 1:7.1p2-1)
bullseye: resolved (fixed in 1:7.1p2-1)
forky: resolved (fixed in 1:7.1p2-1)
sid: resolved (fixed in 1:7.1p2-1)
trixie: resolved (fixed in 1:7.1p2-1)
Apple
CVE-2016-0777: OS X El Capitan v10.11.4 and Security Update 2016-002
vendor_apple·CVSS 6.5
CVE-2016-0777 [MEDIUM] CVE-2016-0777: OS X El Capitan v10.11.4 and Security Update 2016-002
Apple Security Update: About the security content of OS X El Capitan v10.11.4 and Security Update 2016-002
Product: OS X El Capitan v10.11.4 and Security Update 2016-002
CVE: CVE-2016-0777
Component: CVE-ID
Suricata
ET EXPLOIT Possible CVE-2016-0777 Server Advertises Suspicious Roaming Support
suricata·2016-01-15·CVSS 6.5
CVE-2016-0777 [MEDIUM] ET EXPLOIT Possible CVE-2016-0777 Server Advertises Suspicious Roaming Support
ET EXPLOIT Possible CVE-2016-0777 Server Advertises Suspicious Roaming Support
Rule: alert ssh any $SSH_PORTS -> any any (msg:"ET EXPLOIT Possible CVE-2016-0777 Server Advertises Suspicious Roaming Support"; flow:established,to_client; content:"|14|"; offset:6; content:"[email protected]"; distance:0; content:!"AppGateSSH_5.2"; reference:cve,2016-0777; reference:url,www.qualys.com/2016/01/14/cve-2016-0777-cve-2016-0778/openssh-cve-2016-0777-cve-2016-0778.txt; classtype:attempted-user; sid:2022369; rev:2; metadata:created_at 2016_01_15, cve CVE_2016_0777, confidence Medium, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2019_07_26;)
Suricata
ET EXPLOIT Possible CVE-2016-0777 Client Sent Roaming Resume Request
suricata·2016-01-15·CVSS 6.5
CVE-2016-0777 [MEDIUM] ET EXPLOIT Possible CVE-2016-0777 Client Sent Roaming Resume Request
ET EXPLOIT Possible CVE-2016-0777 Client Sent Roaming Resume Request
Rule: alert tcp any any -> any $SSH_PORTS (msg:"ET EXPLOIT Possible CVE-2016-0777 Client Sent Roaming Resume Request"; flow:established,to_server; content:"|14|"; offset:6; content:"[email protected]"; distance:0; content:!"AppGateSSH_5.2"; reference:cve,2016-0777; reference:url,www.qualys.com/2016/01/14/cve-2016-0777-cve-2016-0778/openssh-cve-2016-0777-cve-2016-0778.txt; classtype:attempted-user; sid:2022370; rev:2; metadata:created_at 2016_01_15, cve CVE_2016_0777, confidence Medium, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2019_07_26;)
No public exploits indexed.
Bugzilla
CVE-2016-8605 guile: Thread-unsafe umask modification
bugzilla·2016-10-12·CVSS 5.3
CVE-2016-8605 [MEDIUM] CVE-2016-8605 guile: Thread-unsafe umask modification
CVE-2016-8605 guile: Thread-unsafe umask modification
The mkdir procedure of GNU Guile, an implementation of the Scheme programming language, temporarily changed the process' umask to zero. During that time window, in a multithreaded application, other threads could end up creating files with insecure permissions. For example, mkdir without the optional mode argument would create directories as 0777.
Upstream bug:
http://debbugs.gnu.org/cgi/bugreport.cgi?bug=24659
Upstream patch:
http://git.savannah.gnu.org/cgit/guile.git/commit/?h=stable-2.0&id=245608911698adb3472803856019bdd5670b6614
References:
http://seclists.org/oss-sec/2016/q4/92
Discussion:
Created compat-guile18 tracking bugs for this issue:
Affects: fedora-all [bug 1383974]
Affects: epel-7 [bug 1383975]
---
Created gui
Bugzilla
CVE-2016-0777 CVE-2016-0778 gsi-openssh: various flaws [epel-7]
bugzilla·2016-01-15·CVSS 6.5
CVE-2016-0777 [MEDIUM] CVE-2016-0777 CVE-2016-0778 gsi-openssh: various flaws [epel-7]
CVE-2016-0777 CVE-2016-0778 gsi-openssh: various flaws [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-7 tracking bug for gsi-openssh: see blocks bug list for full
Bugzilla
CVE-2016-0777 CVE-2016-0778 gsi-openssh: various flaws [fedora-all]
bugzilla·2016-01-15·CVSS 6.5
CVE-2016-0777 [MEDIUM] CVE-2016-0777 CVE-2016-0778 gsi-openssh: various flaws [fedora-all]
CVE-2016-0777 CVE-2016-0778 gsi-openssh: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. Wh
Bugzilla
CVE-2016-0777 OpenSSH: Client Information leak due to use of roaming connection feature [fedora-all]
bugzilla·2016-01-14·CVSS 6.5
CVE-2016-0777 [MEDIUM] CVE-2016-0777 OpenSSH: Client Information leak due to use of roaming connection feature [fedora-all]
CVE-2016-0777 OpenSSH: Client Information leak due to use of roaming connection feature [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple
Bugzilla
CVE-2016-0777 OpenSSH: Client Information leak due to use of roaming connection feature
bugzilla·2016-01-13·CVSS 6.5
CVE-2016-0777 [MEDIUM] CVE-2016-0777 OpenSSH: Client Information leak due to use of roaming connection feature
CVE-2016-0777 OpenSSH: Client Information leak due to use of roaming connection feature
The OpenSSH client supports an undocumented feature called roaming: if the connection to an SSH server breaks unexpectedly, and if the server supports roaming as well, the client is able to reconnect to the server and resume the suspended SSH session.
This roaming feature on OpenSSH clients contain a security flaw which allows a malicious SSH server to steal the client's private keys.
Discussion:
Mitigation:
1. The vulnerable roaming code can be permanently disabled by adding the
undocumented option "UseRoaming no" to the system-wide configuration
file (usually /etc/ssh/ssh_config), or per-user configuration file
(~/.ssh/config), or command-line (-o "UseRoaming no").
2. If an OpenSSH client is dis
Bugzilla
CVE-2016-0778 OpenSSH: Client buffer-overflow when using roaming connections
bugzilla·2016-01-13·CVSS 8.1
CVE-2016-0778 [HIGH] CVE-2016-0778 OpenSSH: Client buffer-overflow when using roaming connections
CVE-2016-0778 OpenSSH: Client buffer-overflow when using roaming connections
A buffer-overflow was found in the way OpenSSH client handled roaming connections. This buffer overflow, is present in the default configuration of the OpenSSH client but its exploitation requires two non-default options: a ProxyCommand, and either ForwardAgent (-A) or ForwardX11 (-X).
This buffer-overflow is not exploitable in the default configuration of OpenSSH package shipped with Red Hat Enterprise Linux.
Discussion:
Acknowledgements:
Red Hat would like to thank Qualys for reporting this issue.
---
Created openssh tracking bugs for this issue:
Affects: fedora-all [bug 1298630]
---
Public now via upstream release 7.1p2:
http://www.openssh.com/txt/release-7.1p2
---
A detailed analysis of this issue
arXiv
Cybersecurity as a Service
arxiv_fulltext·2024-02-21
Cybersecurity as a Service
Cybersecurity as a Service
John Morris^* Stefan Tatschner^* Michael P. Heinl Patrizia Heinl Thomas Newe Sven Plaga
*These authors contributed equally to this work.
Authors:
- John Morris^*; Department of Electronic and Computer Engineering, University of Limerick, Ireland; [email protected]; ORCID: https://orcid.org/0000-0003-2811-1055
- Stefan Tatschner^* Fraunhofer AISEC, Department Product Protection and Industrial Security, Germany; Department of Electronic and Computer Engineering, University of Limerick, Ireland; Confirm, the SFI Centre for Smart Manufacturing, Ireland;
[email protected]; ORCID: https://orcid.org/0000-0002-2288-9010
- Michael P. Heinl; Fraunhofer AISEC, Department Product Protection and Industrial Security, Germany; [email protected]
arXiv
Understanding Internet of Things Malware by Analyzing Endpoints in their Static Artifacts
arxiv_fulltext·2021-03-26
Understanding Internet of Things Malware by Analyzing Endpoints in their Static Artifacts
Understanding Internet of Things Malware by Analyzing Endpoints in their Static Artifacts
Afsah Anwar^1, Jinchun Choi^1,2, Abdulrahman Alabduljabbar^1, Hisham Alasmary^1,3,
Jeffrey Spaulding^4, An Wang^5, Songqing Chen^6, DaeHun Nyang^7, Amro Awad^8, and David Mohaisen^1
^1 University of Central Florida
2mm^2 Texas A&M University 2mm^3 King Khalid University 2mm^4 Canisius College
2mm^5 Case Western Reserve University
2mm^6 GMU 2mm^7 Ewha Womans University 2mm^8 NCSU
## Abstract
The lack of security measures among the Internet of Things (IoT) devices and their persistent online connection gives adversaries a prime opportunity to target them or even abuse them as intermediary targets in larger attacks such as distributed denial-of-service (DDoS) campaigns. In this paper, we analyze IoT m
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10734http://lists.apple.com/archives/security-announce/2016/Mar/msg00004.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/176516.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-January/175592.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-January/175676.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-January/176349.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00014.htmlhttp://packetstormsecurity.com/files/135273/Qualys-Security-Advisory-OpenSSH-Overflow-Leak.htmlhttp://seclists.org/fulldisclosure/2016/Jan/44http://www.debian.org/security/2016/dsa-3446http://www.openssh.com/txt/release-7.1p2http://www.openwall.com/lists/oss-security/2016/01/14/7http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.securityfocus.com/archive/1/537295/100/0/threadedhttp://www.securityfocus.com/bid/80695http://www.securitytracker.com/id/1034671http://www.ubuntu.com/usn/USN-2869-1https://blogs.sophos.com/2016/02/17/utm-up2date-9-354-released/https://blogs.sophos.com/2016/02/29/utm-up2date-9-319-released/https://bto.bluecoat.com/security-advisory/sa109https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdfhttps://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05247375https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05356388https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05385680https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722https://security.FreeBSD.org/advisories/FreeBSD-SA-16:07.openssh.aschttps://security.gentoo.org/glsa/201601-01https://support.apple.com/HT206167http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10734http://lists.apple.com/archives/security-announce/2016/Mar/msg00004.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/176516.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-January/175592.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-January/175676.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-January/176349.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00014.htmlhttp://packetstormsecurity.com/files/135273/Qualys-Security-Advisory-OpenSSH-Overflow-Leak.htmlhttp://seclists.org/fulldisclosure/2016/Jan/44http://www.debian.org/security/2016/dsa-3446http://www.openssh.com/txt/release-7.1p2http://www.openwall.com/lists/oss-security/2016/01/14/7http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.securityfocus.com/archive/1/537295/100/0/threadedhttp://www.securityfocus.com/bid/80695http://www.securitytracker.com/id/1034671http://www.ubuntu.com/usn/USN-2869-1https://blogs.sophos.com/2016/02/17/utm-up2date-9-354-released/https://blogs.sophos.com/2016/02/29/utm-up2date-9-319-released/https://bto.bluecoat.com/security-advisory/sa109https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdfhttps://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05247375https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05356388https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05385680https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722https://security.FreeBSD.org/advisories/FreeBSD-SA-16:07.openssh.aschttps://security.gentoo.org/glsa/201601-01https://support.apple.com/HT206167
2016-01-14
Published