sshd in OpenSSH 6.8 and 6.9 uses world-writable permissions for TTY devices, which allows local users to cause a denial of service (terminal disruption) or possibly have unspecified other impact by writing to a device, as demonstrated by writing an escape sequence.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2015-08-23 18:59
Updated : 2022-12-13 04:15
NVD link : CVE-2015-6565
Mitre link : CVE-2015-6565
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
openbsd
- openssh