ALPINE-CVE-2016-10012 PUBLISHED CVSS 7.800000190734863 HIGH

The shared memory manager (associated with pre-authentication compression) in sshd in OpenSSH before 7.4 does not ensure that a bounds check is enforced by all compilers, which might allows local users to gain privileges by leveraging access to a sandboxed privilege-separation process, related to the m_zback and m_zlib data structures.

Risk Scores

CVSS v3.0
7.800000190734863
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Alpine:v3.17openssh6.2_p2-r2, 6.3_p1-r0, 6.3_p1-r1
Alpine:v3.14openssh6.2_p2-r2, 6.3_p1-r0, 6.3_p1-r1
Alpine:v3.18openssh6.6_p1-r0, 5.3_p1-r3, 5.2_p1-r3
Alpine:v3.3openssh5.9_p1-r0, 5.9_p1-r1, 5.9_p1-r2
Alpine:v3.12openssh6.8_p1-r2, 0, 5.1_p1-r1
Alpine:v3.10openssh5.1_p1-r1, 5.1_p1-r2, 5.1p1-r0
Alpine:v3.23openssh6.8_p1-r1, 7.3_p1-r1, 7.3_p1-r0
Alpine:v3.21openssh6.2_p2-r2, 6.3_p1-r0, 6.3_p1-r1
Alpine:v3.13openssh5.4_p1-r1, 0, 5.1_p1-r1
Alpine:v3.15openssh5.8_p2-r2, 6.9_p1-r5, 7.1_p1-r0
Alpine:v3.16openssh7.3_p1-r2, 7.3_p1-r2, 7.3_p1-r1
Alpine:v3.19openssh6.3_p1-r1, 6.6_p1-r4, 6.6_p1-r3
Alpine:v3.11openssh7.3_p1-r3, 7.2_p2-r3, 7.2_p1-r3
Alpine:v3.22openssh5.2_p1-r1, 6.6_p1-r6, 6.7_p1-r0
Alpine:v3.5openssh7.2_p2-r1, 0, 5.1_p1-r1
Alpine:v3.4openssh0, 5.1_p1-r1, 5.1_p1-r2
Alpine:v3.7openssh5.2_p1-r3, 0, 5.1_p1-r1
Alpine:v3.9openssh5.2_p1-r1, 5.2_p1-r0, 5.1p1-r0
Alpine:v3.20openssh5.1_p1-r1, 0, 7.3_p1-r2
Alpine:v3.8openssh6.2_p2-r2, 5.3_p1-r3, 5.4_p1-r0

…and 1 more

Timeline

References

Open in Interactive Console →