CVE-2016-10708
21.01.2018, 22:29
sshd in OpenSSH before 7.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence NEWKEYS message, as demonstrated by Honggfuzz, related to kex.c and packet.c.Enginsight
| Vendor | Product | Version |
|---|---|---|
| openbsd | openssh | 𝑥 < 7.4 |
| debian | debian_linux | 7.0 |
| debian | debian_linux | 8.0 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 18.04 |
| netapp | cloud_backup | - |
| netapp | data_ontap | - |
| netapp | data_ontap_edge | - |
| netapp | oncommand_unified_manager | 9.4 ≤ |
| netapp | service_processor | - |
| netapp | storagegrid | - |
| netapp | storagegrid_webscale | - |
| netapp | clustered_data_ontap | - |
| netapp | vasa_provider | - |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References