1.9
CVSSv2

CVE-2015-6563

Published: 24/08/2015 Updated: 13/12/2022
CVSS v2 Base Score: 1.9 | Impact Score: 2.9 | Exploitability Score: 3.4
VMScore: 169
Vector: AV:L/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The monitor component in sshd in OpenSSH prior to 7.0 on non-OpenBSD platforms accepts extraneous username data in MONITOR_REQ_PAM_INIT_CTX requests, which allows local users to conduct impersonation attacks by leveraging any SSH login access in conjunction with control of the sshd uid to send a crafted MONITOR_REQ_PWNAM request, related to monitor.c and monitor_wrap.c.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openbsd openssh

apple mac os x

Vendor Advisories

Synopsis Moderate: openssh security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic Updated openssh packages that fix multiple security issues, several bugs,and add various enhancements are now available for Red Hat EnterpriseLinux 7Red Hat Product Security has rated this u ...
Debian Bug report logs - #795711 openssh: CVE-2015-6563 CVE-2015-6564 Package: src:openssh; Maintainer for src:openssh is Debian OpenSSH Maintainers <debian-ssh@listsdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Sun, 16 Aug 2015 12:04:21 UTC Severity: important Tags: security Found in version ...
The monitor component in sshd in OpenSSH before 70 on non-OpenBSD platforms accepts extraneous username data in MONITOR_REQ_PAM_INIT_CTX requests, which allows local users to conduct impersonation attacks by leveraging any SSH login access in conjunction with control of the sshd uid to send a crafted MONITOR_REQ_PWNAM request, related to monitorc ...
A flaw was found in the way OpenSSH handled PAM authentication when using privilege separation An attacker with valid credentials on the system and able to fully compromise a non-privileged pre-authentication process using a different flaw could use this flaw to authenticate as other users It was discovered that the OpenSSH sshd daemon did not ch ...
A flaw was found in the way OpenSSH handled PAM authentication when using privilege separation An attacker with valid credentials on the system and able to fully compromise a non-privileged pre-authentication process using a different flaw could use this flaw to authenticate as other users ...

Github Repositories

Contains scripts which may help to identify susceptiblea and vulnerable hosts or services

manual-detection Contains scripts which may help to identify susceptiblea and vulnerable hosts or services test_openssh_vulnspy A python script which test for both CVE-2015-6563 & CVE-2015-6564 (judging by the OpenSSH version) Should work with both python2(7) and python3 Requirements: None Tested python versions: 2716 373 test_php_vulns A python script which