CVE-2016-1907

Published: 19 January 2016

The ssh_packet_read_poll2 function in packet.c in OpenSSH before 7.1p2 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via crafted network traffic.

Priority

Low

CVSS 3 base score: 5.3

Status

Package Release Status
openssh
Launchpad, Ubuntu, Debian
Upstream
Released (1:7.1p2-1)
Ubuntu 16.04 ESM (Xenial Xerus) Not vulnerable
(1:7.1p2-1)
Ubuntu 14.04 ESM (Trusty Tahr) Not vulnerable
(1:6.6p1-2ubuntu2.4)
Patches:
Upstream: https://anongit.mindrot.org/openssh.git/commit/?id=2fecfd486bdba9f51b3a789277bb0733ca36e1c0