authfile.c in sshd in OpenSSH before 7.4 does not properly consider the effects of realloc on buffer contents, which might allow local users to obtain sensitive private-key information by leveraging access to a privilege-separated child process.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openssh | Openbsd | * | 7.3 (including) |
Red Hat Enterprise Linux 7 | RedHat | openssh-0:7.4p1-11.el7 | * |
Openssh | Ubuntu | precise | * |
Openssh | Ubuntu | precise/esm | * |
Openssh | Ubuntu | trusty | * |
Openssh | Ubuntu | upstream | * |
Openssh | Ubuntu | vivid/stable-phone-overlay | * |
Openssh | Ubuntu | vivid/ubuntu-core | * |
Openssh | Ubuntu | xenial | * |
Openssh | Ubuntu | yakkety | * |