CVE-2001-0872Openssh vulnerability

5 documents5 sources
Severity
7.2HIGHNVD
EPSS
0.2%
top 60.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 21
Latest updateMay 3

Description

OpenSSH 3.0.1 and earlier with UseLogin enabled does not properly cleanse critical environment variables such as LD_PRELOAD, which allows local users to gain root privileges.

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Affected Packages3 packages

NVDopenbsd/openssh3.0.1
NVDredhat/linux7.0, 7.1, 7.2+2
NVDsuse/suse_linux5 versions+4

Patches

🔴Vulnerability Details

2
GHSA
GHSA-65cx-7mf4-2jgg: OpenSSH 32022-05-03
CVEList
CVE-2001-0872: OpenSSH 32002-06-25

📋Vendor Advisories

1
Red Hat
security flaw2001-12-04

💬Community

1
Bugzilla
CVE-2001-0872 security flaw2018-08-16
CVE-2001-0872 — Openbsd Openssh vulnerability | cvebase