cbcvebase.
CVE-2016-10708
published 2018-01-21

CVE-2016-10708: sshd in OpenSSH before 7.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence NEWKEYS…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
sshd in OpenSSH before 7.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence NEWKEYS message, as demonstrated by Honggfuzz, related to kex.c and packet.c.

Affected

17 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianopenssh< openssh 1:7.4p1-1 (bookworm)openssh 1:7.4p1-1 (bookworm)
netapponcommand_unified_manager>= 9.4
openbsdopenssh< 7.47.4
openbsdopenssh>= 0 < 1:7.4p1-11:7.4p1-1
openbsdopenssh>= 0 < 1:7.4p1-11:7.4p1-1
openbsdopenssh>= 0 < 1:7.4p1-11:7.4p1-1
openbsdopenssh>= 0 < 1:7.4p1-11:7.4p1-1
openbsdopenssh>= 0 < 1:6.6p1-2ubuntu2.111:6.6p1-2ubuntu2.11
openbsdopenssh>= 0 < 1:7.2p2-4ubuntu2.61:7.2p2-4ubuntu2.6
openbsdopenssh>= 0 < 1:7.6p1-4ubuntu0.11:7.6p1-4ubuntu0.1
openbsdopenssh>= 0 < 1:7.6p1-4ubuntu0.51:7.6p1-4ubuntu0.5
paloaltopan-os

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH