CVE-2016-10012

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
05/01/2017
Last modified:
12/04/2025

Description

The shared memory manager (associated with pre-authentication compression) in sshd in OpenSSH before 7.4 does not ensure that a bounds check is enforced by all compilers, which might allows local users to gain privileges by leveraging access to a sandboxed privilege-separation process, related to the m_zback and m_zlib data structures.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:* 7.3 (including)


References to Advisories, Solutions, and Tools