Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-10012

Опубликовано: 19 дек. 2016
Источник: redhat
CVSS3: 4.2
CVSS2: 3.6

Описание

The shared memory manager (associated with pre-authentication compression) in sshd in OpenSSH before 7.4 does not ensure that a bounds check is enforced by all compilers, which might allows local users to gain privileges by leveraging access to a sandboxed privilege-separation process, related to the m_zback and m_zlib data structures.

It was found that the boundary checks in the code implementing support for pre-authentication compression could have been optimized out by certain compilers. An attacker able to compromise the privilege-separated process could possibly use this flaw for further attacks against the privileged monitor process.

Отчет

In order to exploit this flaw, the attacker needs to first compromise the sandboxed privilege-separation process by using another security flaw. Because of this restriction for successful exploitation, this issue has been rated as having Low security impact.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4opensshWill not fix
Red Hat Enterprise Linux 5opensshWill not fix
Red Hat Enterprise Linux 6opensshFix deferred
Red Hat Enterprise Linux 7opensshFixedRHSA-2017:202901.08.2017

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-287
https://bugzilla.redhat.com/show_bug.cgi?id=1406293openssh: Bounds check can be evaded in the shared memory manager used by pre-authentication compression support

4.2 Medium

CVSS3

3.6 Low

CVSS2

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 8 лет назад

The shared memory manager (associated with pre-authentication compression) in sshd in OpenSSH before 7.4 does not ensure that a bounds check is enforced by all compilers, which might allows local users to gain privileges by leveraging access to a sandboxed privilege-separation process, related to the m_zback and m_zlib data structures.

CVSS3: 7.8
nvd
больше 8 лет назад

The shared memory manager (associated with pre-authentication compression) in sshd in OpenSSH before 7.4 does not ensure that a bounds check is enforced by all compilers, which might allows local users to gain privileges by leveraging access to a sandboxed privilege-separation process, related to the m_zback and m_zlib data structures.

CVSS3: 7.8
debian
больше 8 лет назад

The shared memory manager (associated with pre-authentication compress ...

CVSS3: 7.8
github
около 3 лет назад

The shared memory manager (associated with pre-authentication compression) in sshd in OpenSSH before 7.4 does not ensure that a bounds check is enforced by all compilers, which might allows local users to gain privileges by leveraging access to a sandboxed privilege-separation process, related to the m_zback and m_zlib data structures.

CVSS3: 7.8
fstec
больше 8 лет назад

Уязвимость менеджера разделяемой памяти демона sshd средства криптографической защиты OpenSSH, позволяющая нарушителю повысить свои привилегии

4.2 Medium

CVSS3

3.6 Low

CVSS2