CVE-2016-0777: Apple Mac OS X

Medium severity, CVSS 6.5. EPSS: 63.5% chance of exploitation in the next 30 days.

The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitive information from process memory by requesting transmission of an entire buffer, as demonstrated by reading a private key.

Affected products

  • Apple Mac OS X: up to and including 10.11.3
  • HP Remote Device Access Virtual Customer Access System: up to and including 15.07
  • OpenBSD OpenSSH: version 5.0 only; version 5.1 only; version 5.2 only; version 5.3 only; version 5.4 only; version 5.5 only; …
  • Oracle Linux: version 7 only
  • Oracle Solaris: version 11.3 only
  • Sophos Unified Threat Management Software: version 9.318 only; version 9.353 only

Published 2016-01-14. Last modified 2026-06-17.