Vulnerability Description
The do_setup_env function in session.c in sshd in OpenSSH through 7.2p2, when the UseLogin feature is enabled and PAM is configured to read .pam_environment files in user home directories, allows local users to gain privileges by triggering a crafted environment for the /bin/login program, as demonstrated by an LD_PRELOAD environment variable.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian | Debian Linux | 7.0 |
| Openbsd | Openssh | <= 7.2 |
| Canonical | Ubuntu Core | 15.04 |
| Canonical | Ubuntu Linux | 12.04 |
| Canonical | Ubuntu Touch | 15.04 |
Related Weaknesses (CWE)
References
- http://rhn.redhat.com/errata/RHSA-2016-2588.html
- http://rhn.redhat.com/errata/RHSA-2017-0641.html
- http://www.debian.org/security/2016/dsa-3550
- http://www.securityfocus.com/bid/86187
- http://www.securitytracker.com/id/1036487
- https://anongit.mindrot.org/openssh.git/commit/?id=85bdcd7c92fe7ff133bbc4e10a65c
- https://bugzilla.redhat.com/show_bug.cgi?id=1328012
- https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf
- https://people.canonical.com/~ubuntu-security/cve/2015/CVE-2015-8325.html
- https://security-tracker.debian.org/tracker/CVE-2015-8325
- https://security.gentoo.org/glsa/201612-18
- https://security.netapp.com/advisory/ntap-20180628-0001/
- http://rhn.redhat.com/errata/RHSA-2016-2588.html
- http://rhn.redhat.com/errata/RHSA-2017-0641.html
- http://www.debian.org/security/2016/dsa-3550
FAQ
What is CVE-2015-8325?
CVE-2015-8325 is a vulnerability with a CVSS score of 7.8 (HIGH). The do_setup_env function in session.c in sshd in OpenSSH through 7.2p2, when the UseLogin feature is enabled and PAM is configured to read .pam_environment files in user home directories, allows loca...
How severe is CVE-2015-8325?
CVE-2015-8325 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-8325?
Check the references section above for vendor advisories and patch information. Affected products include: Debian Debian Linux, Openbsd Openssh, Canonical Ubuntu Core, Canonical Ubuntu Linux, Canonical Ubuntu Touch.