CVE-2016-0777 is an information disclosure vulnerability in OpenSSH client versions 5.x, 6.x, and 7.x before 7.1p2, affecting products from vendors like Apple, HP, and Oracle. A malicious OpenSSH server can exploit a flaw in the resend_bytes function to extract sensitive data, such as private keys, from the client's memory. This medium-severity vulnerability (CVSS 6.5) has a high confidentiality impact, is network-exploitable with low attack complexity, and does not require user interaction. While not listed on the KEV catalog and lacking public exploit code in Metasploit or ExploitDB, it has garnered significant community discussion and media attention, indicating a recognized risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.318CPE matchmatch criteria | cpe:2.3:a:sophos:unified_threat_management_software:9.318:*:*:*:*:*:*:* | ||
9.353CPE matchmatch criteria | cpe:2.3:a:sophos:unified_threat_management_software:9.353:*:*:*:*:*:*:* | ||
7CPE matchmatch criteria | cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:* | ||
11.3CPE matchmatch criteria | cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:* | ||
5.0CPE matchmatch criteria | cpe:2.3:a:openbsd:openssh:5.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
OpenSSH: Client Information leak due to use of roaming connection feature
Jan 14, 2016Information disclosure vulnerability in OpenSSH clients.
Jan 14, 2016Information disclosure in OpenSSH clients via malicious server
Jan 14, 2016OpenSSH clients vulnerable to information disclosure that may allow a malicious server to retrieve private keys.
Jan 14, 2016Information disclosure vulnerability in OpenSSH clients.
Jan 14, 2016