The do_setup_env function in session.c in sshd in OpenSSH through 7.2p2, when the UseLogin feature is enabled and PAM is configured to read .pam_environment files in user home directories, allows local users to gain privileges by triggering a crafted environment for the /bin/login program, as demonstrated by an LD_PRELOAD environment variable.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Information
Published : 2016-04-30 18:59
Updated : 2022-12-13 04:15
NVD link : CVE-2015-8325
Mitre link : CVE-2015-8325
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
openbsd
- openssh
canonical
- ubuntu_core
- ubuntu_linux
- ubuntu_touch
debian
- debian_linux