CVE-2016-0777

medium
Published 2016-01-14 · Modified 2026-05-06
CVSS v3
6.5
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS v2
4.0
VIR risk
6.5

Description

The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitive information from process memory by requesting transmission of an entire buffer, as demonstrated by reading a private key.

Predictions

Exploit likelihood
75%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2016-0777

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://www.openssh.com/txt/release-7.1p2

OS impact

OSVersionStatusFixed in
macos macosaffected
debian debianbookwormfixed1:7.1p2-1
debian debianbullseyefixed1:7.1p2-1
debian debianforkyfixed1:7.1p2-1
debian debiansidfixed1:7.1p2-1
debian debiantrixiefixed1:7.1p2-1

Application impact

VendorProductVersionsFixed
sophosunified_threat_management_software9.318
sophosunified_threat_management_software9.353
openbsdopenssh5.0
openbsdopenssh5.1
openbsdopenssh5.2
openbsdopenssh5.3
openbsdopenssh5.4
openbsdopenssh5.5
openbsdopenssh5.6
openbsdopenssh5.7
openbsdopenssh5.8
openbsdopenssh5.9
openbsdopenssh6.0
openbsdopenssh6.1
openbsdopenssh6.2
openbsdopenssh6.3
openbsdopenssh6.4
openbsdopenssh6.5
openbsdopenssh6.6
openbsdopenssh6.7
openbsdopenssh6.8
openbsdopenssh6.9
openbsdopenssh7.0
openbsdopenssh7.1
hp hpremote_device_access_virtual_customer_access_system{"endIncluding":"15.07"}

References

CWEs

CWE-200

Verify integrity in audit chain (admin only). AS-IS.