CVE-2016-10012

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

The shared memory manager (associated with pre-authentication compression) in sshd in OpenSSH before 7.4 does not ensure that a bounds check is enforced by all compilers, which might allows local users to gain privileges by leveraging access to a sandboxed privilege-separation process, related to the m_zback and m_zlib data structures.

References

http://www.openwall.com/lists/oss-security/2016/12/19/2

http://www.securityfocus.com/bid/94975

http://www.securitytracker.com/id/1037490

http://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.647637

https://access.redhat.com/errata/RHSA-2017:2029

https://github.com/openbsd/src/commit/3095060f479b86288e31c79ecbc5131a66bcd2f9

https://lists.debian.org/debian-lts-announce/2018/09/msg00010.html

https://security.netapp.com/advisory/ntap-20171130-0002/

https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03818en_us

https://www.openssh.com/txt/release-7.4

Details

Source: MITRE

Published: 2017-01-05

Updated: 2018-09-11

Type: CWE-119

Risk Information

CVSS v2

Base Score: 7.2

Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 3.9

Severity: HIGH

CVSS v3

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 1.8

Severity: HIGH

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:* versions up to 7.3 (inclusive)

Tenable Plugins

View all (25 total)

IDNameProductFamilySeverity
148681Juniper Junos OS Multiple Vulnerabilities (JSA11169)NessusJunos Local Security Checks
high
138037Palo Alto Networks PAN-OS 7.1.x < 7.1.26 / 8.0.x < 8.1.13 / 8.1.x < 8.1.13 / 9.0.x < 9.0.1 VulnerabilityNessusPalo Alto Local Security Checks
high
136324AIX OpenSSH Advisory : openssh_advisory10.ascNessusAIX Local Security Checks
high
132547F5 Networks BIG-IP : OpenSSH vulnerability (K62201745)NessusF5 Networks Local Security Checks
high
130514Juniper JSA10940NessusJunos Local Security Checks
high
126510Juniper Junos Space < 18.2R1 Multiple Vulnerabilities (JSA10880)NessusJunos Local Security Checks
high
121665Photon OS 1.0: Openssh PHSA-2017-0001NessusPhotonOS Local Security Checks
high
118498SUSE SLES11 Security Update : openssh (SUSE-SU-2018:3540-1)NessusSuSE Local Security Checks
high
117452SUSE SLES12 Security Update : openssh (SUSE-SU-2018:2685-1)NessusSuSE Local Security Checks
high
111850Photon OS 1.0: Libxml2 / Linux / Openssh PHSA-2017-0001 (deprecated)NessusPhotonOS Local Security Checks
high
111639SUSE SLES11 Security Update : openssh (SUSE-SU-2018:2275-1)NessusSuSE Local Security Checks
high
106266Ubuntu 14.04 LTS / 16.04 LTS / 17.10 : openssh vulnerabilities (USN-3538-1)NessusUbuntu Local Security Checks
high
103650Amazon Linux AMI : openssh (ALAS-2017-898)NessusAmazon Linux Local Security Checks
high
102751CentOS 7 : openssh (CESA-2017:2029)NessusCentOS Local Security Checks
high
102650Scientific Linux Security Update : openssh on SL7.x x86_64 (20170801)NessusScientific Linux Local Security Checks
high
102296Oracle Linux 7 : openssh (ELSA-2017-2029)NessusOracle Linux Local Security Checks
high
102226EulerOS 2.0 SP2 : openssh (EulerOS-SA-2017-1139)NessusHuawei Local Security Checks
high
102225EulerOS 2.0 SP1 : openssh (EulerOS-SA-2017-1138)NessusHuawei Local Security Checks
high
102112RHEL 7 : openssh (RHSA-2017:2029)NessusRed Hat Local Security Checks
high
99134macOS 10.12.x < 10.12.4 Multiple Vulnerabilities (httpoxy)NessusMacOS X Local Security Checks
critical
96919openSUSE Security Update : openssh (openSUSE-2017-184)NessusSuSE Local Security Checks
high
96718SUSE SLED12 / SLES12 Security Update : openssh (SUSE-SU-2017:0264-1)NessusSuSE Local Security Checks
high
9855OpenSSH 7.x < 7.4 Multiple VulnerabilitiesNessus Network MonitorSSH
high
96151OpenSSH < 7.4 Multiple VulnerabilitiesNessusMisc.
high
96091Slackware 13.0 / 13.1 / 13.37 / 14.0 / 14.1 / 14.2 / current : openssh (SSA:2016-358-02)NessusSlackware Local Security Checks
high