Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:12384
HistoryJan 15, 2019 - 9:16 a.m.

Privilege Escalation

2019-01-1509:16:33
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

0.0004 Low

EPSS

Percentile

5.1%

openssh is vulnerable to privilege escalation. It was discovered that the OpenSSH sshd daemon fetched PAM environment settings before running the login program. In configurations with UseLogin=yes and the pam_env PAM module configured to read user environment settings, a local user could use this flaw to execute arbitrary code as root.

References