CVE

Id
95678  
CVE No.
CVE-2016-8858  
Status
Candidate  
Description
** DISPUTED ** The kex_input_kexinit function in kex.c in OpenSSH 6.x and 7.x through 7.3 allows remote attackers to cause a denial of service (memory consumption) by sending many duplicate KEXINIT requests. NOTE: a third party reports that "OpenSSH upstream does not consider this as a security issue."  
Phase
Assigned (20161019)  
Votes
None (candidate not yet proposed)  
Comments