PoC Index

CVE-2016-0778

HIGH 8.1EPSS 20.9%

The (1) roaming_read and (2) roaming_write functions in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2, when certain proxy and forward options are enabled, do not properly maintain connection file descriptors, which allows remote servers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact by requesting many forwardings.

CVSS v3.1
8.1 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v3.0
8.1 HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
4.6 MEDIUMAV:N/AC:H/Au:S/C:P/I:P/A:P
EPSS
20.90% chance of exploitation in the next 30 days, 97th percentile
Published
2016-01-14
Updated
2026-05-29

Proof-of-concept exploits (5)

References

Related