Lucene search

K
f5F5F5:K64292204
HistoryJan 24, 2017 - 12:00 a.m.

K64292204 : OpenSSH vulnerability CVE-2016-10010

2017-01-2400:00:00
my.f5.com
70

7.1 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

0.4%

Security Advisory Description

sshd in OpenSSH before 7.4, when privilege separation is not used, creates forwarded Unix-domain sockets as root, which might allow local users to gain privileges via unspecified vectors, related to serverloop.c. (CVE-2016-10010)

Impact

In the default configuration, there is no impact. However, if the administrator disables privilege separation in the system sshd_config file, the system can be exposed to this vulnerability.