The (1) roamingread and (2) roamingwrite functions in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2, when certain proxy and forward options are enabled, do not properly maintain connection file descriptors, which allows remote servers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact by requesting many forwardings.
{
"unresolved_ranges": [
{
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:openbsd:openssh:5.8:*:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "5.8"
}
]
},
{
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:openbsd:openssh:6.2:*:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "6.2"
}
]
},
{
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:openbsd:openssh:7.1:*:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "7.1"
}
]
},
{
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:sophos:unified_threat_management_software:9.353:*:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "9.353"
}
]
},
{
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "10.9.0"
},
{
"last_affected": "10.9.5"
},
{
"introduced": "10.10.0"
},
{
"last_affected": "10.10.5"
},
{
"introduced": "10.11.0"
},
{
"last_affected": "10.11.3"
}
]
},
{
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:hp:virtual_customer_access_system:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "15.07"
}
]
},
{
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "7"
}
]
},
{
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "11.3"
}
]
}
]
}{
"source": "CPE_FIELD",
"cpe": [
"cpe:2.3:a:openbsd:openssh:5.4:*:*:*:*:*:*:*",
"cpe:2.3:a:openbsd:openssh:5.4:p1:*:*:*:*:*:*",
"cpe:2.3:a:openbsd:openssh:5.5:*:*:*:*:*:*:*",
"cpe:2.3:a:openbsd:openssh:5.5:p1:*:*:*:*:*:*",
"cpe:2.3:a:openbsd:openssh:5.6:*:*:*:*:*:*:*",
"cpe:2.3:a:openbsd:openssh:5.6:p1:*:*:*:*:*:*",
"cpe:2.3:a:openbsd:openssh:5.7:*:*:*:*:*:*:*",
"cpe:2.3:a:openbsd:openssh:5.7:p1:*:*:*:*:*:*",
"cpe:2.3:a:openbsd:openssh:5.8:p1:*:*:*:*:*:*",
"cpe:2.3:a:openbsd:openssh:5.9:*:*:*:*:*:*:*",
"cpe:2.3:a:openbsd:openssh:5.9:p1:*:*:*:*:*:*",
"cpe:2.3:a:openbsd:openssh:6.0:*:*:*:*:*:*:*",
"cpe:2.3:a:openbsd:openssh:6.0:p1:*:*:*:*:*:*",
"cpe:2.3:a:openbsd:openssh:6.1:*:*:*:*:*:*:*",
"cpe:2.3:a:openbsd:openssh:6.1:p1:*:*:*:*:*:*",
"cpe:2.3:a:openbsd:openssh:6.2:p1:*:*:*:*:*:*",
"cpe:2.3:a:openbsd:openssh:6.2:p2:*:*:*:*:*:*",
"cpe:2.3:a:openbsd:openssh:6.3:*:*:*:*:*:*:*",
"cpe:2.3:a:openbsd:openssh:6.3:p1:*:*:*:*:*:*",
"cpe:2.3:a:openbsd:openssh:6.4:*:*:*:*:*:*:*",
"cpe:2.3:a:openbsd:openssh:6.4:p1:*:*:*:*:*:*",
"cpe:2.3:a:openbsd:openssh:6.5:*:*:*:*:*:*:*",
"cpe:2.3:a:openbsd:openssh:6.5:p1:*:*:*:*:*:*",
"cpe:2.3:a:openbsd:openssh:6.6:*:*:*:*:*:*:*",
"cpe:2.3:a:openbsd:openssh:6.6:p1:*:*:*:*:*:*",
"cpe:2.3:a:openbsd:openssh:6.7:*:*:*:*:*:*:*",
"cpe:2.3:a:openbsd:openssh:6.7:p1:*:*:*:*:*:*",
"cpe:2.3:a:openbsd:openssh:6.8:*:*:*:*:*:*:*",
"cpe:2.3:a:openbsd:openssh:6.8:p1:*:*:*:*:*:*",
"cpe:2.3:a:openbsd:openssh:6.9:*:*:*:*:*:*:*",
"cpe:2.3:a:openbsd:openssh:6.9:p1:*:*:*:*:*:*",
"cpe:2.3:a:openbsd:openssh:7.0:*:*:*:*:*:*:*",
"cpe:2.3:a:openbsd:openssh:7.0:p1:*:*:*:*:*:*",
"cpe:2.3:a:openbsd:openssh:7.1:p1:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "5.4"
},
{
"last_affected": "5.4-p1"
},
{
"last_affected": "5.5"
},
{
"last_affected": "5.5-p1"
},
{
"last_affected": "5.6"
},
{
"last_affected": "5.6-p1"
},
{
"last_affected": "5.7"
},
{
"last_affected": "5.7-p1"
},
{
"last_affected": "5.8-p1"
},
{
"last_affected": "5.9"
},
{
"last_affected": "5.9-p1"
},
{
"last_affected": "6.0"
},
{
"last_affected": "6.0-p1"
},
{
"last_affected": "6.1"
},
{
"last_affected": "6.1-p1"
},
{
"last_affected": "6.2-p1"
},
{
"last_affected": "6.2-p2"
},
{
"last_affected": "6.3"
},
{
"last_affected": "6.3-p1"
},
{
"last_affected": "6.4"
},
{
"last_affected": "6.4-p1"
},
{
"last_affected": "6.5"
},
{
"last_affected": "6.5-p1"
},
{
"last_affected": "6.6"
},
{
"last_affected": "6.6-p1"
},
{
"last_affected": "6.7"
},
{
"last_affected": "6.7-p1"
},
{
"last_affected": "6.8"
},
{
"last_affected": "6.8-p1"
},
{
"last_affected": "6.9"
},
{
"last_affected": "6.9-p1"
},
{
"last_affected": "7.0"
},
{
"last_affected": "7.0-p1"
},
{
"last_affected": "7.1-p1"
}
]
}