Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cm6p-9f8w-c878

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7

Описание

Use-after-free vulnerability in the mm_answer_pam_free_ctx function in monitor.c in sshd in OpenSSH before 7.0 on non-OpenBSD platforms might allow local users to gain privileges by leveraging control of the sshd uid to send an unexpectedly early MONITOR_REQ_PAM_FREE_CTX request.

Use-after-free vulnerability in the mm_answer_pam_free_ctx function in monitor.c in sshd in OpenSSH before 7.0 on non-OpenBSD platforms might allow local users to gain privileges by leveraging control of the sshd uid to send an unexpectedly early MONITOR_REQ_PAM_FREE_CTX request.

EPSS

Процентиль: 45%
0.00604
Низкий

7 High

CVSS3

Дефекты

CWE-416

Связанные уязвимости

CVSS3: 7
ubuntu
почти 11 лет назад

Use-after-free vulnerability in the mm_answer_pam_free_ctx function in monitor.c in sshd in OpenSSH before 7.0 on non-OpenBSD platforms might allow local users to gain privileges by leveraging control of the sshd uid to send an unexpectedly early MONITOR_REQ_PAM_FREE_CTX request.

redhat
почти 11 лет назад

Use-after-free vulnerability in the mm_answer_pam_free_ctx function in monitor.c in sshd in OpenSSH before 7.0 on non-OpenBSD platforms might allow local users to gain privileges by leveraging control of the sshd uid to send an unexpectedly early MONITOR_REQ_PAM_FREE_CTX request.

CVSS3: 7
nvd
почти 11 лет назад

Use-after-free vulnerability in the mm_answer_pam_free_ctx function in monitor.c in sshd in OpenSSH before 7.0 on non-OpenBSD platforms might allow local users to gain privileges by leveraging control of the sshd uid to send an unexpectedly early MONITOR_REQ_PAM_FREE_CTX request.

CVSS3: 7
debian
почти 11 лет назад

Use-after-free vulnerability in the mm_answer_pam_free_ctx function in ...

CVSS3: 7.4
fstec
почти 11 лет назад

Уязвимость функции mm_answer_pam_free_ctx средства криптографической защиты OpenSSH, позволяющая нарушителю выполнить произвольный код или остановить службу sshd

EPSS

Процентиль: 45%
0.00604
Низкий

7 High

CVSS3

Дефекты

CWE-416