OpenSSH does not properly drop privileges when the UseLogin option is enabled, which allows local users to execute arbitrary commands by providing the command to the ssh daemon.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/4646 | vdb entry |
http://www.openbsd.org/errata.html#uselogin | vendor advisory |
http://www.osvdb.org/341 | vdb entry |
http://archives.neohapsis.com/archives/bugtraq/2000-06/0065.html | mailing list |
http://www.securityfocus.com/bid/1334 | vdb entry |