PT-2016-3440 · Openssh+6 · Openssh+6
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenSSH versions through 7.2p2
Description
The issue allows local users to gain privileges by triggering a crafted environment for the /bin/login program, as demonstrated by an
LD PRELOAD environment variable. This is related to the do setup env function in session.c in sshd when the UseLogin feature is enabled and PAM is configured to read .pam environment files in user home directories. There is also a mention of a potential denial of service via long password strings in password authentication.Recommendations
For OpenSSH versions through 7.2p2, consider disabling the
UseLogin feature or restricting the use of .pam environment files in user home directories until a patch is available. As a temporary workaround, restrict access to the do setup env function in session.c to minimize the risk of exploitation. Avoid using long strings in password authentication to prevent denial of service attacks.Exploit
Correção
DoS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Centos
Ibm Aix
Openssh
Red Hat
Suse
Ubuntu