6.9
CVSSv2

CVE-2015-6564

Published: 24/08/2015 Updated: 13/12/2022
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Use-after-free vulnerability in the mm_answer_pam_free_ctx function in monitor.c in sshd in OpenSSH prior to 7.0 on non-OpenBSD platforms might allow local users to gain privileges by leveraging control of the sshd uid to send an unexpectedly early MONITOR_REQ_PAM_FREE_CTX request.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openbsd openssh

Vendor Advisories

Synopsis Moderate: openssh security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic Updated openssh packages that fix multiple security issues, several bugs,and add various enhancements are now available for Red Hat EnterpriseLinux 7Red Hat Product Security has rated this u ...
Debian Bug report logs - #795711 openssh: CVE-2015-6563 CVE-2015-6564 Package: src:openssh; Maintainer for src:openssh is Debian OpenSSH Maintainers <debian-ssh@listsdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Sun, 16 Aug 2015 12:04:21 UTC Severity: important Tags: security Found in version ...
The monitor component in sshd in OpenSSH before 70 on non-OpenBSD platforms accepts extraneous username data in MONITOR_REQ_PAM_INIT_CTX requests, which allows local users to conduct impersonation attacks by leveraging any SSH login access in conjunction with control of the sshd uid to send a crafted MONITOR_REQ_PWNAM request, related to monitorc ...
A flaw was found in the way OpenSSH handled PAM authentication when using privilege separation An attacker with valid credentials on the system and able to fully compromise a non-privileged pre-authentication process using a different flaw could use this flaw to authenticate as other users It was discovered that the OpenSSH sshd daemon did not ch ...
A use-after-free flaw was found in OpenSSH An attacker able to fully compromise a non-privileged pre-authentication process using a different flaw could possibly cause sshd to crash or execute arbitrary code with root privileges ...

Github Repositories

Contains scripts which may help to identify susceptiblea and vulnerable hosts or services

manual-detection Contains scripts which may help to identify susceptiblea and vulnerable hosts or services test_openssh_vulnspy A python script which test for both CVE-2015-6563 & CVE-2015-6564 (judging by the OpenSSH version) Should work with both python2(7) and python3 Requirements: None Tested python versions: 2716 373 test_php_vulns A python script which