cbcvebase.
CVE-2015-8325
published 2016-05-01

CVE-2015-8325: The do_setup_env function in session.c in sshd in OpenSSH through 7.2p2, when the UseLogin feature is enabled and PAM is configured to read .pam_environment…

high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
The do_setup_env function in session.c in sshd in OpenSSH through 7.2p2, when the UseLogin feature is enabled and PAM is configured to read .pam_environment files in user home directories, allows local users to gain privileges by triggering a crafted environment for the /bin/login program, as demonstrated by an LD_PRELOAD environment variable.

Affected

15 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_core
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_touch
debiandebian_linux
debiandebian_linux
debianopenssh< openssh 1:7.2p2-3 (bookworm)openssh 1:7.2p2-3 (bookworm)
openbsdopenssh<= 7.2
openbsdopenssh>= 0 < 1:7.2p2-31:7.2p2-3
openbsdopenssh>= 0 < 1:7.2p2-31:7.2p2-3
openbsdopenssh>= 0 < 1:7.2p2-31:7.2p2-3
openbsdopenssh>= 0 < 1:7.2p2-31:7.2p2-3
openbsdopenssh>= 0 < 1:6.6p1-2ubuntu2.71:6.6p1-2ubuntu2.7
paloaltopan-os

CVSS provenance

nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH