{"id":"ECHO-195a-a2de-ff9a","summary":"This vulnerability is disputed by the opensh maintainers and is considered\nexpected behavior.\nhttps://security-tracker.debian.org/tracker/CVE-2016-20012\nhttps://github.com/openssh/openssh-portable/pull/270\nhttps://www.openwall.com/lists/oss-security/2018/08/24/1\n","modified":"2026-09-15T03:42:37.585349968Z","published":"2026-01-29T00:50:36.588077Z","withdrawn":"2025-08-03T16:59:07.240Z","upstream":["CVE-2016-20012","GHSA-84j4-ccmw-hwpg"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2016-20012"}],"affected":[{"package":{"name":"openssh","ecosystem":"Echo","purl":"pkg:deb/echo/openssh"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:9.2p1-2+deb12u6"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-195a-a2de-ff9a.json"}}],"schema_version":"1.9.0"}