Описание
The do_setup_env function in session.c in sshd in OpenSSH through 7.2p2, when the UseLogin feature is enabled and PAM is configured to read .pam_environment files in user home directories, allows local users to gain privileges by triggering a crafted environment for the /bin/login program, as demonstrated by an LD_PRELOAD environment variable.
Релиз | Статус | Примечание |
---|---|---|
devel | not-affected | 1:7.2p2-3 |
esm-infra-legacy/trusty | released | 1:6.6p1-2ubuntu2.7 |
esm-infra/xenial | not-affected | 1:7.2p2-3 |
precise | released | 1:5.9p1-5ubuntu1.9 |
precise/esm | not-affected | 1:5.9p1-5ubuntu1.9 |
trusty | released | 1:6.6p1-2ubuntu2.7 |
trusty/esm | released | 1:6.6p1-2ubuntu2.7 |
upstream | released | 1:7.2p2-3 |
vivid/stable-phone-overlay | ignored | end of life |
vivid/ubuntu-core | ignored | end of life |
Показывать по
EPSS
7.2 High
CVSS2
7.8 High
CVSS3
Связанные уязвимости
The do_setup_env function in session.c in sshd in OpenSSH through 7.2p2, when the UseLogin feature is enabled and PAM is configured to read .pam_environment files in user home directories, allows local users to gain privileges by triggering a crafted environment for the /bin/login program, as demonstrated by an LD_PRELOAD environment variable.
The do_setup_env function in session.c in sshd in OpenSSH through 7.2p2, when the UseLogin feature is enabled and PAM is configured to read .pam_environment files in user home directories, allows local users to gain privileges by triggering a crafted environment for the /bin/login program, as demonstrated by an LD_PRELOAD environment variable.
The do_setup_env function in session.c in sshd in OpenSSH through 7.2p ...
The do_setup_env function in session.c in sshd in OpenSSH through 7.2p2, when the UseLogin feature is enabled and PAM is configured to read .pam_environment files in user home directories, allows local users to gain privileges by triggering a crafted environment for the /bin/login program, as demonstrated by an LD_PRELOAD environment variable.
ELSA-2017-0641: openssh security and bug fix update (MODERATE)
EPSS
7.2 High
CVSS2
7.8 High
CVSS3