CVE-2016-1235: Debian Linux

High severity, CVSS 8.8. EPSS: 3.4% chance of exploitation in the next 30 days.

The oarsh script in OAR before 2.5.7 allows remote authenticated users of a cluster to obtain sensitive information and possibly gain privileges via vectors related to OpenSSH options.

Affected products

Published 2016-04-11. Last modified 2026-06-17.