CVE-2016-10011

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

authfile.c in sshd in OpenSSH before 7.4 does not properly consider the effects of realloc on buffer contents, which might allow local users to obtain sensitive private-key information by leveraging access to a privilege-separated child process.

References

https://github.com/openbsd/src/commit/ac8147a06ed2e2403fb6b9a0c03e618a9333c0e9

http://www.openwall.com/lists/oss-security/2016/12/19/2

https://www.openssh.com/txt/release-7.4

http://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.647637

http://www.securitytracker.com/id/1037490

http://www.securityfocus.com/bid/94977

https://security.netapp.com/advisory/ntap-20171130-0002/

https://access.redhat.com/errata/RHSA-2017:2029

https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03818en_us

https://lists.debian.org/debian-lts-announce/2018/09/msg00010.html

https://cert-portal.siemens.com/productcert/pdf/ssa-676336.pdf

Details

Source: MITRE

Published: 2017-01-05

Updated: 2021-09-14

Type: CWE-320

Risk Information

CVSS v2

Base Score: 2.1

Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Impact Score: 2.9

Exploitability Score: 3.9

Severity: LOW

CVSS v3

Base Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Impact Score: 3.6

Exploitability Score: 1.8

Severity: MEDIUM

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:* versions up to 7.3 (inclusive)

Tenable Plugins

View all (25 total)

IDNameProductFamilySeverity
148681Juniper Junos OS Multiple Vulnerabilities (JSA11169)NessusJunos Local Security Checks
high
136324AIX OpenSSH Advisory : openssh_advisory10.ascNessusAIX Local Security Checks
high
130514Juniper JSA10940NessusJunos Local Security Checks
high
126510Juniper Junos Space < 18.2R1 Multiple Vulnerabilities (JSA10880)NessusJunos Local Security Checks
high
119733F5 Networks BIG-IP : OpenSSH vulnerability (K24324390)NessusF5 Networks Local Security Checks
medium
106266Ubuntu 14.04 LTS / 16.04 LTS / 17.10 : openssh vulnerabilities (USN-3538-1)NessusUbuntu Local Security Checks
high
103650Amazon Linux AMI : openssh (ALAS-2017-898)NessusAmazon Linux Local Security Checks
high
102751CentOS 7 : openssh (CESA-2017:2029)NessusCentOS Local Security Checks
high
102650Scientific Linux Security Update : openssh on SL7.x x86_64 (20170801)NessusScientific Linux Local Security Checks
high
102296Oracle Linux 7 : openssh (ELSA-2017-2029)NessusOracle Linux Local Security Checks
high
102112RHEL 7 : openssh (RHSA-2017:2029)NessusRed Hat Local Security Checks
high
99900EulerOS 2.0 SP1 : openssh (EulerOS-SA-2017-1055)NessusHuawei Local Security Checks
high
99899EulerOS 2.0 SP2 : openssh (EulerOS-SA-2017-1054)NessusHuawei Local Security Checks
high
99134macOS 10.12.x < 10.12.4 Multiple Vulnerabilities (httpoxy)NessusMacOS X Local Security Checks
critical
97716openSUSE Security Update : openssh (openSUSE-2017-339)NessusSuSE Local Security Checks
high
97653SUSE SLES12 Security Update : openssh (SUSE-SU-2017:0607-3)NessusSuSE Local Security Checks
high
97652SUSE SLED12 Security Update : openssh (SUSE-SU-2017:0607-2)NessusSuSE Local Security Checks
high
97571SUSE SLES12 Security Update : openssh (SUSE-SU-2017:0607-1)NessusSuSE Local Security Checks
high
97570SUSE SLES11 Security Update : openssh (SUSE-SU-2017:0606-1)NessusSuSE Local Security Checks
high
97549SUSE SLES11 Security Update : openssh (SUSE-SU-2017:0603-1)NessusSuSE Local Security Checks
high
96919openSUSE Security Update : openssh (openSUSE-2017-184)NessusSuSE Local Security Checks
high
96718SUSE SLED12 / SLES12 Security Update : openssh (SUSE-SU-2017:0264-1)NessusSuSE Local Security Checks
high
9855OpenSSH 7.x < 7.4 Multiple VulnerabilitiesNessus Network MonitorSSH
high
96151OpenSSH < 7.4 Multiple VulnerabilitiesNessusMisc.
high
96091Slackware 13.0 / 13.1 / 13.37 / 14.0 / 14.1 / 14.2 / current : openssh (SSA:2016-358-02)NessusSlackware Local Security Checks
high