CVE-2016-10011
MEDIUMOpenSSH <7.4 - Info Disclosure
Title source: llmDescription
authfile.c in sshd in OpenSSH before 7.4 does not properly consider the effects of realloc on buffer contents, which might allow local users to obtain sensitive private-key information by leveraging access to a privilege-separated child process.
References (12)
Scores
CVSS v3
5.5
EPSS
0.0002
EPSS Percentile
3.7%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-320
Status
published
Affected Products (2)
openbsd/openssh
< 7.3
n/a/n/a
Timeline
Published
Jan 05, 2017
Tracked Since
Feb 18, 2026