Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2015-8325
Description:The do_setup_env function in session.c in sshd in OpenSSH through 7.2p2, when the UseLogin feature is enabled and PAM is configured to read .pam_environment files in user home directories, allows local users to gain privileges by triggering a crafted environment for the /bin/login program, as demonstrated by an LD_PRELOAD environment variable.
Test IDs: 1.3.6.1.4.1.25623.1.0.871696   1.3.6.1.4.1.25623.1.0.871779   1.3.6.1.4.1.25623.1.0.808394   1.3.6.1.4.1.25623.1.1.2.2016.1053   1.3.6.1.4.1.25623.1.1.10.2016.0280   1.3.6.1.4.1.25623.1.0.807950   1.3.6.1.4.1.25623.1.0.808369   1.3.6.1.4.1.25623.1.0.807574   1.3.6.1.4.1.25623.1.0.703550  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2015-8325
BugTraq ID: 86187
http://www.securityfocus.com/bid/86187
Debian Security Information: DSA-3550 (Google Search)
http://www.debian.org/security/2016/dsa-3550
https://security.gentoo.org/glsa/201612-18
RedHat Security Advisories: RHSA-2016:2588
http://rhn.redhat.com/errata/RHSA-2016-2588.html
RedHat Security Advisories: RHSA-2017:0641
http://rhn.redhat.com/errata/RHSA-2017-0641.html
http://www.securitytracker.com/id/1036487




© 1998-2025 E-Soft Inc. All rights reserved.