Описание
The (1) roaming_read and (2) roaming_write functions in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2, when certain proxy and forward options are enabled, do not properly maintain connection file descriptors, which allows remote servers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact by requesting many forwardings.
Релиз | Статус | Примечание |
---|---|---|
devel | not-affected | 1:7.1p2-2 |
esm-infra-legacy/trusty | not-affected | 1:6.6p1-2ubuntu2.4 |
precise | released | 1:5.9p1-5ubuntu1.8 |
trusty | released | 1:6.6p1-2ubuntu2.4 |
trusty/esm | not-affected | 1:6.6p1-2ubuntu2.4 |
upstream | released | 7.1p2 |
vivid | released | 1:6.7p1-5ubuntu1.4 |
vivid/stable-phone-overlay | released | 1:6.7p1-5ubuntu1.4 |
vivid/ubuntu-core | released | 1:6.7p1-5ubuntu1.4 |
wily | released | 1:6.9p1-2ubuntu0.1 |
Показывать по
Ссылки на источники
EPSS
4.6 Medium
CVSS2
8.1 High
CVSS3
Связанные уязвимости
The (1) roaming_read and (2) roaming_write functions in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2, when certain proxy and forward options are enabled, do not properly maintain connection file descriptors, which allows remote servers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact by requesting many forwardings.
The (1) roaming_read and (2) roaming_write functions in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2, when certain proxy and forward options are enabled, do not properly maintain connection file descriptors, which allows remote servers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact by requesting many forwardings.
The (1) roaming_read and (2) roaming_write functions in roaming_common ...
The (1) roaming_read and (2) roaming_write functions in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2, when certain proxy and forward options are enabled, do not properly maintain connection file descriptors, which allows remote servers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact by requesting many forwardings.
Уязвимость функций roaming_read и roaming_write средства криптографической защиты OpenSSH, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
4.6 Medium
CVSS2
8.1 High
CVSS3