CVE-2016-1907: Buffer Overflow
Published Jan 19, 2016
·Updated
Last updated 24 July 2024
Other sources
The sshpacketreadpoll2 function in packet.c in OpenSSH before 7.1p2 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via crafted network traffic.
Affected Software
9 affected componentsFixes available
debian/openssh
1:8.4p1-5+deb11u31:9.2p1-2+deb12u31:9.8p1-8
OpenBSD OpenSSH=6.8
OpenBSD OpenSSH=6.8-p1
OpenBSD OpenSSH=6.9
OpenBSD OpenSSH=6.9-p1
OpenBSD OpenSSH=7.0
OpenBSD OpenSSH=7.0-p1
OpenBSD OpenSSH=7.1
OpenBSD OpenSSH=7.1-p1
Remediation
Event History
Jan 19, 2016
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:15 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·01:09 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-1907?
CVE-2016-1907 is classified as a denial of service vulnerability that can cause application crashes.
2
How do I fix CVE-2016-1907?
To fix CVE-2016-1907, update OpenSSH to versions 7.1p2 or later.
3
Which versions of OpenSSH are affected by CVE-2016-1907?
OpenSSH versions before 7.1p2 are affected by CVE-2016-1907.
4
Can CVE-2016-1907 be exploited remotely?
Yes, CVE-2016-1907 can be exploited remotely through crafted network traffic.
5
What can attackers achieve using CVE-2016-1907?
Attackers can cause an out-of-bounds read and crash the OpenSSH application using CVE-2016-1907.