Back to search
CVE-2016-0778
Published: Jan 14, 2016
Modified: May 29, 2026
PUBLISHED
Description
The (1) roaming_read and (2) roaming_write functions in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2, when certain proxy and forward options are enabled, do not properly maintain connection file descriptors, which allows remote servers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact by requesting many forwardings.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
SUSE-SU-2016:0117
vendor-advisory
APPLE-SA-2016-03-21-5
vendor-advisory
FEDORA-2016-4556904561
vendor-advisory
openSUSE-SU-2016:0128
vendor-advisory
80698
vdb-entry
FEDORA-2016-2e89eba0c1
vendor-advisory
1034671
vdb-entry
openSUSE-SU-2016:0127
vendor-advisory
GLSA-201601-01
vendor-advisory
SUSE-SU-2016:0119
vendor-advisory
SUSE-SU-2016:0118
vendor-advisory
SUSE-SU-2016:0120
vendor-advisory
USN-2869-1
vendor-advisory
DSA-3446
vendor-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now