oss-sec mailing list archives

CVE request - OpenSSH 6.9 PAM privilege separation vulnerabilities


From: Moritz Jodeit <moritz () bluefrostsecurity de>
Date: Tue, 11 Aug 2015 20:40:38 +0200

Hello list,

could you please assign two CVE IDs for the following two security
issues fixed in OpenSSH 7.0 (directly taken from the release notes [1]):

 * sshd(8): Portable OpenSSH only: Fixed a privilege separation
   weakness related to PAM support. Attackers who could successfully
   compromise the pre-authentication process for remote code
   execution and who had valid credentials on the host could
   impersonate other users.  Reported by Moritz Jodeit.

 * sshd(8): Portable OpenSSH only: Fixed a use-after-free bug
   related to PAM support that was reachable by attackers who could
   compromise the pre-authentication process for remote code
   execution. Also reported by Moritz Jodeit.

[1] http://www.openssh.com/txt/release-7.0

Thank you,
Moritz


Current thread: