CVE Vulnerabilities

CVE-2016-10011

Published: Jan 05, 2017 | Modified: Dec 13, 2022
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
1 LOW
AV:L/AC:H/Au:S/C:P/I:N/A:N
RedHat/V3
2.5 LOW
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Ubuntu
LOW

authfile.c in sshd in OpenSSH before 7.4 does not properly consider the effects of realloc on buffer contents, which might allow local users to obtain sensitive private-key information by leveraging access to a privilege-separated child process.

Affected Software

Name Vendor Start Version End Version
Openssh Openbsd * 7.3 (including)
Red Hat Enterprise Linux 7 RedHat openssh-0:7.4p1-11.el7 *
Openssh Ubuntu precise *
Openssh Ubuntu precise/esm *
Openssh Ubuntu trusty *
Openssh Ubuntu upstream *
Openssh Ubuntu vivid/stable-phone-overlay *
Openssh Ubuntu vivid/ubuntu-core *
Openssh Ubuntu xenial *
Openssh Ubuntu yakkety *

References