Lucene search

K
f5F5F5:K20911042
HistoryMay 16, 2016 - 12:00 a.m.

K20911042 : OpenSSH vulnerability CVE-2015-8325

2016-05-1600:00:00
my.f5.com
38

7.5 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

Security Advisory Description

The do_setup_env function in session.c in sshd in OpenSSH through 7.2p2, when the UseLogin feature is enabled and PAM is configured to read .pam_environment files in user home directories, allows local users to gain privileges by triggering a crafted environment for the /bin/login program, as demonstrated by an LD_PRELOAD environment variable. (CVE-2015-8325)
Impact
When this vulnerability is exploited, local users may be able to gain privileges on the system.