← Back to CVE List
Vulnerability Intelligence Report

CVE-2016-0778

The (1) roaming_read and (2) roaming_write functions in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2, when certain proxy and forward options are enabled, do not properly maintain connection file descriptors, which allows remote servers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact by requesting many forwardings.

No Active Exploit Signals
CVSS Base Score
8.1
HIGH
Exploitability:2.3
Impact Score:5.9
EPSS Probability:20.37%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-119 ↗CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

Affected Products & Versions

Vendor Product Affected Versions
oracle linux 7
oracle solaris 11.3
openbsd openssh 5.4, 5.5, 5.6, 5.7, 5.8, 5.9, 6.0, 6.1, 6.2, 6.3, 6.4, 6.5, 6.6, 6.7, 6.8, 6.9, 7.0, 7.1
apple mac_os_x all
hp virtual_customer_access_system all
sophos unified_threat_management_software 9.353

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
20.370%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityRed Hat, Inc. · Vendor · USA
Reserved2015-12-16T00:00:00
Published2016-01-14T00:00:00
Patch Date2016-01-14
Last Updated2026-05-29T20:28:32

LINK COPIED TO CLIPBOARD