7.2
CVSSv2

CVE-2001-0872

Published: 21/12/2001 Updated: 03/05/2018
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

OpenSSH 3.0.1 and previous versions with UseLogin enabled does not properly cleanse critical environment variables such as LD_PRELOAD, which allows local users to gain root privileges.

Vulnerable Product Search on Vulmon Subscribe to Product

openbsd openssh

suse suse linux 6.4

suse suse linux 7.0

suse suse linux 7.1

suse suse linux 7.2

redhat linux 7.0

suse suse linux 7.3

redhat linux 7.1

redhat linux 7.2

Vendor Advisories

If the UseLogin feature is enabled in ssh local users could pass environment variables (including variables like LD_PRELOAD) to the login process This has been fixed by not copying the environment if UseLogin is enabled Please note that the default configuration for Debian does not have UseLogin enabled This has been fixed in version 1:123-94 ...