The resendbytes function in roamingcommon.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitive information from process memory by requesting transmission of an entire buffer, as demonstrated by reading a private key.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "5.0"
},
{
"introduced": "0"
},
{
"last_affected": "5.0-p1"
},
{
"introduced": "0"
},
{
"last_affected": "5.1"
},
{
"introduced": "0"
},
{
"last_affected": "5.1-p1"
},
{
"introduced": "0"
},
{
"last_affected": "5.2"
},
{
"introduced": "0"
},
{
"last_affected": "5.2-p1"
},
{
"introduced": "0"
},
{
"last_affected": "5.3"
},
{
"introduced": "0"
},
{
"last_affected": "5.3-p1"
},
{
"introduced": "0"
},
{
"last_affected": "5.4"
},
{
"introduced": "0"
},
{
"last_affected": "5.4-p1"
},
{
"introduced": "0"
},
{
"last_affected": "5.5"
},
{
"introduced": "0"
},
{
"last_affected": "5.5-p1"
},
{
"introduced": "0"
},
{
"last_affected": "5.6"
},
{
"introduced": "0"
},
{
"last_affected": "5.6-p1"
},
{
"introduced": "0"
},
{
"last_affected": "5.7"
},
{
"introduced": "0"
},
{
"last_affected": "5.7-p1"
},
{
"introduced": "0"
},
{
"last_affected": "5.8-p1"
},
{
"introduced": "0"
},
{
"last_affected": "5.9"
},
{
"introduced": "0"
},
{
"last_affected": "5.9-p1"
},
{
"introduced": "0"
},
{
"last_affected": "6.0"
},
{
"introduced": "0"
},
{
"last_affected": "6.0-p1"
},
{
"introduced": "0"
},
{
"last_affected": "6.1"
},
{
"introduced": "0"
},
{
"last_affected": "6.1-p1"
},
{
"introduced": "0"
},
{
"last_affected": "6.2-p1"
},
{
"introduced": "0"
},
{
"last_affected": "6.2-p2"
},
{
"introduced": "0"
},
{
"last_affected": "6.3"
},
{
"introduced": "0"
},
{
"last_affected": "6.3-p1"
},
{
"introduced": "0"
},
{
"last_affected": "6.4"
},
{
"introduced": "0"
},
{
"last_affected": "6.4-p1"
},
{
"introduced": "0"
},
{
"last_affected": "6.5"
},
{
"introduced": "0"
},
{
"last_affected": "6.5-p1"
},
{
"introduced": "0"
},
{
"last_affected": "6.6"
},
{
"introduced": "0"
},
{
"last_affected": "6.6-p1"
},
{
"introduced": "0"
},
{
"last_affected": "6.7"
},
{
"introduced": "0"
},
{
"last_affected": "6.7-p1"
},
{
"introduced": "0"
},
{
"last_affected": "6.8"
},
{
"introduced": "0"
},
{
"last_affected": "6.8-p1"
},
{
"introduced": "0"
},
{
"last_affected": "6.9"
},
{
"introduced": "0"
},
{
"last_affected": "6.9-p1"
},
{
"introduced": "0"
},
{
"last_affected": "7.0"
},
{
"introduced": "0"
},
{
"last_affected": "7.0-p1"
},
{
"introduced": "0"
},
{
"last_affected": "7.1-p1"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-0777.json"
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.318"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.353"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "11.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "5.8"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "6.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "15.07"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "10.11.3"
}
]
}
]