CVE-2016-0778
published 2016-01-14CVE-2016-0778: The (1) roaming_read and (2) roaming_write functions in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2, when certain proxy and…
PriorityP355high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
20.37%
97.2th percentile
The (1) roaming_read and (2) roaming_write functions in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2, when certain proxy and forward options are enabled, do not properly maintain connection file descriptors, which allows remote servers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact by requesting many forwardings.
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | 10.10.0 – 10.10.5 | — |
| apple | mac_os_x | 10.11.0 – 10.11.3 | — |
| apple | mac_os_x | 10.9.0 – 10.9.5 | — |
| apple | os_x_el_capitan_v10.11.4_and_security_update_2016-002 | — | — |
| debian | openssh | < openssh 1:7.1p2-1 (bookworm) | openssh 1:7.1p2-1 (bookworm) |
| hp | virtual_customer_access_system | <= 15.07 | — |
| openbsd | openssh | — | — |
| openbsd | openssh | — | — |
| openbsd | openssh | — | — |
| openbsd | openssh | — | — |
| openbsd | openssh | — | — |
| openbsd | openssh | — | — |
| openbsd | openssh | — | — |
| openbsd | openssh | — | — |
| openbsd | openssh | — | — |
| openbsd | openssh | — | — |
| openbsd | openssh | — | — |
| openbsd | openssh | — | — |
| openbsd | openssh | — | — |
| openbsd | openssh | — | — |
| openbsd | openssh | — | — |
| openbsd | openssh | — | — |
| openbsd | openssh | — | — |
| openbsd | openssh | — | — |
| openbsd | openssh | >= 0 < 1:7.1p2-1 | 1:7.1p2-1 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:N/AC:H/Au:S/C:P/I:P/A:P
osv8.1HIGH
vendor_debian8.1HIGH
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SCALANCE X-200RNA Switch Devices
cisa_ics·2022-12-19
Siemens SCALANCE X-200RNA Switch Devices
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SCALANCE X-200RNA Switch Devices
Last RevisedDecember 19, 2022
Alert CodeICSA-22-349-21
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity/public exploits are available
- Vendor: Siemens
- Equipment: SCALANCE X-200RNA switch devices before V3.2.7
- Vulnerabilities: Observable Timing Discrepancy; Race Condition; Improper Restriction of Operations within the Bounds of a Memory Buffer; Improper Input Validation; NULL Pointer Dereference; Use After Free; Cryptographic Issues; Comparison of Incompatible Types; Resource Management
Palo Alto
PAN-SA-2016-0011 OpenSSH vulnerabilities
vendor_paloalto·2016-07-12·CVSS 6.5
CVE-2016-0777 [MEDIUM] CWE-119 PAN-SA-2016-0011 OpenSSH vulnerabilities
PAN-SA-2016-0011 OpenSSH vulnerabilities
OpenSSH contains two vulnerabilities (CVE-2016-0777 and CVE-2016-0778) affecting the SSH client roaming feature when connecting to a malicious server.
CVEs: CVE-2016-0777, CVE-2016-0778
Affected products: PAN-OS
Ubuntu
OpenSSH vulnerabilities
vendor_ubuntu·2016-01-14
CVE-2016-0777 OpenSSH vulnerabilities
Title: OpenSSH vulnerabilities
Summary: OpenSSH could be made to expose sensitive information over the network.
It was discovered that the OpenSSH client experimental support for resuming
connections contained multiple security issues. A malicious server could
use this issue to leak client memory to the server, including private
client user keys.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
OpenSSH: Client buffer-overflow when using roaming connections
vendor_redhat·2016-01-14·CVSS 8.1
CVE-2016-0778 [HIGH] CWE-122 OpenSSH: Client buffer-overflow when using roaming connections
OpenSSH: Client buffer-overflow when using roaming connections
The (1) roaming_read and (2) roaming_write functions in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2, when certain proxy and forward options are enabled, do not properly maintain connection file descriptors, which allows remote servers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact by requesting many forwardings.
A buffer overflow flaw was found in the way the OpenSSH client roaming feature was implemented. A malicious server could potentially use this flaw to execute arbitrary code on a successfully authenticated OpenSSH client if that client used certain non-default configuration options.
Package: openssh (Red Hat Enterprise Linux 4) - Not aff
Debian
CVE-2016-0778: openssh - The (1) roaming_read and (2) roaming_write functions in roaming_common.c in the ...
vendor_debian·2016·CVSS 8.1
CVE-2016-0778 [HIGH] CVE-2016-0778: openssh - The (1) roaming_read and (2) roaming_write functions in roaming_common.c in the ...
The (1) roaming_read and (2) roaming_write functions in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2, when certain proxy and forward options are enabled, do not properly maintain connection file descriptors, which allows remote servers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact by requesting many forwardings.
Scope: local
bookworm: resolved (fixed in 1:7.1p2-1)
bullseye: resolved (fixed in 1:7.1p2-1)
forky: resolved (fixed in 1:7.1p2-1)
sid: resolved (fixed in 1:7.1p2-1)
trixie: resolved (fixed in 1:7.1p2-1)
Apple
CVE-2016-0778: OS X El Capitan v10.11.4 and Security Update 2016-002
vendor_apple·CVSS 8.1
CVE-2016-0778 [HIGH] CVE-2016-0778: OS X El Capitan v10.11.4 and Security Update 2016-002
Apple Security Update: About the security content of OS X El Capitan v10.11.4 and Security Update 2016-002
Product: OS X El Capitan v10.11.4 and Security Update 2016-002
CVE: CVE-2016-0778
Component: CVE-ID
VulDB
OpenSSH up to 5.x/6.x/7.1p1 Forward Option roaming_common.c roaming_read/roaming_write memory corruption (USN-2869-1 / Nessus ID 87972)
vuldb·2026-05-29·CVSS 8.1
CVE-2016-0778 [HIGH] OpenSSH up to 5.x/6.x/7.1p1 Forward Option roaming_common.c roaming_read/roaming_write memory corruption (USN-2869-1 / Nessus ID 87972)
A vulnerability was found in OpenSSH up to 5.x/6.x/7.1p1 and classified as critical. Affected is the function roaming_read/roaming_write of the file roaming_common.c of the component Forward Option Handler. Executing a manipulation can lead to memory corruption.
This vulnerability is handled as CVE-2016-0778. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
VulDB
Apple Mac OS X up to 10.11.3 OpenSSH Key memory corruption (HT206167 / Nessus ID 90096)
vuldb·2026-05-29·CVSS 8.1
CVE-2016-0778 [HIGH] Apple Mac OS X up to 10.11.3 OpenSSH Key memory corruption (HT206167 / Nessus ID 90096)
A vulnerability classified as problematic has been found in Apple Mac OS X up to 10.11.3. Affected is an unknown function of the component OpenSSH. Performing a manipulation results in memory corruption (Key).
This vulnerability is known as CVE-2016-0778. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.
GHSA
GHSA-cqpr-rfm2-cchc: The (1) roaming_read and (2) roaming_write functions in roaming_common
ghsa_unreviewed·2022-05-13
CVE-2016-0778 [HIGH] CWE-119 GHSA-cqpr-rfm2-cchc: The (1) roaming_read and (2) roaming_write functions in roaming_common
The (1) roaming_read and (2) roaming_write functions in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2, when certain proxy and forward options are enabled, do not properly maintain connection file descriptors, which allows remote servers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact by requesting many forwardings.
OSV
CVE-2016-0778: The (1) roaming_read and (2) roaming_write functions in roaming_common
osv·2016-01-14·CVSS 8.1
CVE-2016-0778 [HIGH] CVE-2016-0778: The (1) roaming_read and (2) roaming_write functions in roaming_common
The (1) roaming_read and (2) roaming_write functions in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2, when certain proxy and forward options are enabled, do not properly maintain connection file descriptors, which allows remote servers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact by requesting many forwardings.
Suricata
ET EXPLOIT Possible CVE-2016-0777 Server Advertises Suspicious Roaming Support
suricata·2016-01-15·CVSS 6.5
CVE-2016-0777 [MEDIUM] ET EXPLOIT Possible CVE-2016-0777 Server Advertises Suspicious Roaming Support
ET EXPLOIT Possible CVE-2016-0777 Server Advertises Suspicious Roaming Support
Rule: alert ssh any $SSH_PORTS -> any any (msg:"ET EXPLOIT Possible CVE-2016-0777 Server Advertises Suspicious Roaming Support"; flow:established,to_client; content:"|14|"; offset:6; content:"[email protected]"; distance:0; content:!"AppGateSSH_5.2"; reference:cve,2016-0777; reference:url,www.qualys.com/2016/01/14/cve-2016-0777-cve-2016-0778/openssh-cve-2016-0777-cve-2016-0778.txt; classtype:attempted-user; sid:2022369; rev:2; metadata:created_at 2016_01_15, cve CVE_2016_0777, confidence Medium, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2019_07_26;)
Suricata
ET EXPLOIT Possible CVE-2016-0777 Client Sent Roaming Resume Request
suricata·2016-01-15·CVSS 6.5
CVE-2016-0777 [MEDIUM] ET EXPLOIT Possible CVE-2016-0777 Client Sent Roaming Resume Request
ET EXPLOIT Possible CVE-2016-0777 Client Sent Roaming Resume Request
Rule: alert tcp any any -> any $SSH_PORTS (msg:"ET EXPLOIT Possible CVE-2016-0777 Client Sent Roaming Resume Request"; flow:established,to_server; content:"|14|"; offset:6; content:"[email protected]"; distance:0; content:!"AppGateSSH_5.2"; reference:cve,2016-0777; reference:url,www.qualys.com/2016/01/14/cve-2016-0777-cve-2016-0778/openssh-cve-2016-0777-cve-2016-0778.txt; classtype:attempted-user; sid:2022370; rev:2; metadata:created_at 2016_01_15, cve CVE_2016_0777, confidence Medium, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2019_07_26;)
No public exploits indexed.
Bugzilla
CVE-2016-0777 CVE-2016-0778 gsi-openssh: various flaws [epel-7]
bugzilla·2016-01-15·CVSS 6.5
CVE-2016-0777 [MEDIUM] CVE-2016-0777 CVE-2016-0778 gsi-openssh: various flaws [epel-7]
CVE-2016-0777 CVE-2016-0778 gsi-openssh: various flaws [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-7 tracking bug for gsi-openssh: see blocks bug list for full
Bugzilla
CVE-2016-0777 CVE-2016-0778 gsi-openssh: various flaws [fedora-all]
bugzilla·2016-01-15·CVSS 6.5
CVE-2016-0777 [MEDIUM] CVE-2016-0777 CVE-2016-0778 gsi-openssh: various flaws [fedora-all]
CVE-2016-0777 CVE-2016-0778 gsi-openssh: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. Wh
Bugzilla
CVE-2016-0778 OpenSSH: Client buffer-overflow when using roaming connections [fedora-all]
bugzilla·2016-01-14·CVSS 8.1
CVE-2016-0778 [HIGH] CVE-2016-0778 OpenSSH: Client buffer-overflow when using roaming connections [fedora-all]
CVE-2016-0778 OpenSSH: Client buffer-overflow when using roaming connections [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
Bugzilla
CVE-2016-0777 OpenSSH: Client Information leak due to use of roaming connection feature
bugzilla·2016-01-13·CVSS 6.5
CVE-2016-0777 [MEDIUM] CVE-2016-0777 OpenSSH: Client Information leak due to use of roaming connection feature
CVE-2016-0777 OpenSSH: Client Information leak due to use of roaming connection feature
The OpenSSH client supports an undocumented feature called roaming: if the connection to an SSH server breaks unexpectedly, and if the server supports roaming as well, the client is able to reconnect to the server and resume the suspended SSH session.
This roaming feature on OpenSSH clients contain a security flaw which allows a malicious SSH server to steal the client's private keys.
Discussion:
Mitigation:
1. The vulnerable roaming code can be permanently disabled by adding the
undocumented option "UseRoaming no" to the system-wide configuration
file (usually /etc/ssh/ssh_config), or per-user configuration file
(~/.ssh/config), or command-line (-o "UseRoaming no").
2. If an OpenSSH client is dis
Bugzilla
CVE-2016-0778 OpenSSH: Client buffer-overflow when using roaming connections
bugzilla·2016-01-13·CVSS 8.1
CVE-2016-0778 [HIGH] CVE-2016-0778 OpenSSH: Client buffer-overflow when using roaming connections
CVE-2016-0778 OpenSSH: Client buffer-overflow when using roaming connections
A buffer-overflow was found in the way OpenSSH client handled roaming connections. This buffer overflow, is present in the default configuration of the OpenSSH client but its exploitation requires two non-default options: a ProxyCommand, and either ForwardAgent (-A) or ForwardX11 (-X).
This buffer-overflow is not exploitable in the default configuration of OpenSSH package shipped with Red Hat Enterprise Linux.
Discussion:
Acknowledgements:
Red Hat would like to thank Qualys for reporting this issue.
---
Created openssh tracking bugs for this issue:
Affects: fedora-all [bug 1298630]
---
Public now via upstream release 7.1p2:
http://www.openssh.com/txt/release-7.1p2
---
A detailed analysis of this issue
Trendmicro
Current and Future Attacks Threatening Esports
blogs_trendmicro·2019-10-29
Current and Future Attacks Threatening Esports
Cyber Crime
# Current and Future Attacks Threatening Esports
Cybercriminals will increasingly target the esports industry over the next three years. Many underground forums already have sections dedicated to gaming or esports sales, and the goods and services offered in these forums generate a lot of interest.
By: Mayra Rosario Fuentes, Fernando Merces
2019/10/29
Read time: ( words)
Save to Folio
Esports has evolved from niche entertainment into a highly lucrative industry. Growing ad revenue and sponsorships allow the tournaments to grow; and as the tournaments grow, the prize pool grows as well. Of course, growing popularity and increased funds open up the entities involved to cybercriminals looking for any opportunity to make a profit.
Cheats and hacks are widely available in und
Trendmicro
Current and Future Attacks Threatening Esports
blogs_trendmicro·2019-10-29
Current and Future Attacks Threatening Esports
Cyber Crime
# Current and Future Attacks Threatening Esports
Cybercriminals will increasingly target the esports industry over the next three years. Many underground forums already have sections dedicated to gaming or esports sales, and the goods and services offered in these forums generate a lot of interest.
By: Mayra Rosario Fuentes, Fernando Merces
Oct 29, 2019
Read time: ( words)
Save to Folio
Esports has evolved from niche entertainment into a highly lucrative industry. Growing ad revenue and sponsorships allow the tournaments to grow; and as the tournaments grow, the prize pool grows as well. Of course, growing popularity and increased funds open up the entities involved to cybercriminals looking for any opportunity to make a profit.
Cheats and hacks are widely available in u
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10734http://lists.apple.com/archives/security-announce/2016/Mar/msg00004.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/176516.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-January/176349.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00014.htmlhttp://packetstormsecurity.com/files/135273/Qualys-Security-Advisory-OpenSSH-Overflow-Leak.htmlhttp://seclists.org/fulldisclosure/2016/Jan/44http://www.debian.org/security/2016/dsa-3446http://www.openssh.com/txt/release-7.1p2http://www.openwall.com/lists/oss-security/2016/01/14/7http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.securityfocus.com/archive/1/537295/100/0/threadedhttp://www.securityfocus.com/bid/80698http://www.securitytracker.com/id/1034671http://www.ubuntu.com/usn/USN-2869-1https://blogs.sophos.com/2016/02/17/utm-up2date-9-354-released/https://blogs.sophos.com/2016/02/29/utm-up2date-9-319-released/https://bto.bluecoat.com/security-advisory/sa109https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdfhttps://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05247375https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05356388https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05385680https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722https://security.gentoo.org/glsa/201601-01https://support.apple.com/HT206167http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10734http://lists.apple.com/archives/security-announce/2016/Mar/msg00004.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/176516.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-January/176349.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00014.htmlhttp://packetstormsecurity.com/files/135273/Qualys-Security-Advisory-OpenSSH-Overflow-Leak.htmlhttp://seclists.org/fulldisclosure/2016/Jan/44http://www.debian.org/security/2016/dsa-3446http://www.openssh.com/txt/release-7.1p2http://www.openwall.com/lists/oss-security/2016/01/14/7http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.securityfocus.com/archive/1/537295/100/0/threadedhttp://www.securityfocus.com/bid/80698http://www.securitytracker.com/id/1034671http://www.ubuntu.com/usn/USN-2869-1https://blogs.sophos.com/2016/02/17/utm-up2date-9-354-released/https://blogs.sophos.com/2016/02/29/utm-up2date-9-319-released/https://bto.bluecoat.com/security-advisory/sa109https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdfhttps://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05247375https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05356388https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05385680https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722https://security.gentoo.org/glsa/201601-01https://support.apple.com/HT206167
2016-01-14
Published