sk109636 - Check Point Response to CVE-2016-0777 and CVE-2016-0778 - OpenSSH Client vulnerabilities
Check Point Response to CVE-2016-0777 and CVE-2016-0778 - OpenSSH Client vulnerabilities
Please read this important update from Check Point.
Security Alert:
Low
Product
Security Gateways
Version
R77.30 (EOS), R80 (EOS), R80.10 (EOS), R80.20 (EOS), R80.20SP (EOS), R80.30 (EOS), R80.30SP (EOS), R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20, R82
OS
Gaia
Last Modified
2025-02-09
Symptoms
- Qualys Security team discovered two vulnerabilities in the roaming code of the OpenSSH client ( CVE-2016-0777 and CVE-2016-0778):
SSH roaming enables a client, in case an SSH connection breaks unexpectedly, to resume it at a later time, provided the SSH server also supports it.
Solution
The exploitation scenario is only applicable to OpenSSH client that connects to a malicious SSH Server (e.g., refer to OpenBSD Journal - OpenSSH: client bugs CVE-2016-0777 and CVE-2016-0778).
Check Point Products are not vulnerable because a hardened OpenSSH is used (based on version 4.3).
Article Properties
- Access Level: General
- Severity: Low
- Status: Approved
- Date Created: 2016-01-14
- Last Modified: 2025-02-09