Vulnerability CVE-2016-8858: Information
Description
The kex_input_kexinit function in kex.c in OpenSSH 6.x and 7.x through 7.3 allows remote attackers to cause a denial of service (memory consumption) by sending many duplicate KEXINIT requests. NOTE: a third party reports that "OpenSSH upstream does not consider this as a security issue."
Severity: HIGH (7.5) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
---|---|---|---|---|---|---|
openssh | sisyphus | 7.2p2-alt2 | 9.6p1-alt1 | ALT-PU-2016-2124-1 | 171152 | Fixed |
openssh | p10 | 7.2p2-alt2 | 7.9p1-alt4.p10.6 | ALT-PU-2016-2124-1 | 171152 | Fixed |
openssh | p9 | 7.2p2-alt2 | 7.9p1-alt1 | ALT-PU-2016-2124-1 | 171152 | Fixed |
openssh | p8 | 7.2p2-alt2 | 7.2p2-alt2.M80P.2 | ALT-PU-2016-2137-1 | 171162 | Fixed |
openssh | c10f1 | 7.2p2-alt2 | 7.9p1-alt4.p10.6 | ALT-PU-2016-2124-1 | 171152 | Fixed |
openssh | c9f2 | 7.2p2-alt2 | 7.9p1-alt4.p10.6 | ALT-PU-2016-2124-1 | 171152 | Fixed |
openssh | c7 | 5.9p1-alt7.M70C.2 | 6.7p1-alt1.M70C.5 | ALT-PU-2016-2183-1 | 171159 | Fixed |
openssh | p11 | 7.2p2-alt2 | 9.6p1-alt1 | ALT-PU-2016-2124-1 | 171152 | Fixed |