Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-10708

Опубликовано: 24 янв. 2018
Источник: redhat
CVSS3: 5.3

Описание

sshd in OpenSSH before 7.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence NEWKEYS message, as demonstrated by Honggfuzz, related to kex.c and packet.c.

Отчет

This issue affects the versions of openssh as shipped with Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7 (versions 7.3 and earlier). For Red Hat Enterprise Linux 7 (versions 7.4 and later), this issue was fixed by the Security Advisory RHSA-2017:2029. For Red Hat Enterprise Linux 6, Red Hat Product Security has rated this issue as having Low security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5opensshWill not fix
Red Hat Enterprise Linux 6opensshWill not fix
Red Hat Enterprise Linux 8opensshNot affected
Red Hat Enterprise Linux 7opensshFixedRHSA-2017:202901.08.2017

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1537929openssh: Out of sequence NEWKEYS message can allow remote attacker to cause denial of service

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 8 лет назад

sshd in OpenSSH before 7.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence NEWKEYS message, as demonstrated by Honggfuzz, related to kex.c and packet.c.

CVSS3: 7.5
nvd
около 8 лет назад

sshd in OpenSSH before 7.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence NEWKEYS message, as demonstrated by Honggfuzz, related to kex.c and packet.c.

CVSS3: 7.5
debian
около 8 лет назад

sshd in OpenSSH before 7.4 allows remote attackers to cause a denial o ...

suse-cvrf
больше 7 лет назад

Security update for openssh

suse-cvrf
больше 7 лет назад

Security update for openssh

5.3 Medium

CVSS3