Debian Security Advisory: openssh — security update

Home » Debian » Debian-安全更新 » Debian Security Advisory: openssh — security update
2016-04-17 Debian-安全更新 無迴響

https://security-tracker.debian.org/tracker/CVE-2015-8325

Shayan Sadigh discovered a vulnerability in OpenSSH: If PAM support is enabled and the sshd PAM configuration is configured to read userspecified environment variables and the UseLogin option is enabled, a local user may escalate her privileges to root.

In Debian UseLogin is not enabled by default.

For the oldstable distribution (wheezy), this problem has been fixed in version 6.0p1-4+deb7u4.

For the stable distribution (jessie), this problem has been fixed in version 6.7p1-5+deb8u2.

For the unstable distribution (sid), this problem has been fixed in version 1:7.2p2-3.

We recommend that you upgrade your openssh packages.

LEAVE A COMMENT

請輸入驗證碼 * Time limit is exhausted. Please reload CAPTCHA.