6.5
CVSSv2

CVE-2008-3234

Published: 18/07/2008 Updated: 29/09/2017
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

sshd in OpenSSH 4 on Debian GNU/Linux, and the 20070303 OpenSSH snapshot, allows remote authenticated users to obtain access to arbitrary SELinux roles by appending a :/ (colon slash) sequence, followed by the role name, to the username.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openbsd openssh 4.0

Exploits

/* Debian (maybe other derivates |KUDUBUTUNTU|) OpenSSH Remote -=Authenticated=- SELinux Privilege Elevation *** Fedora/RHEL Linux should be tested because it _MAY_ contain the same vulnerability *** in it's OpenSSH patches in a time slice Latest OpenSSH should not be vulnerable Older Debian Releases may **** One vulnerable example is "openssh-S ...