PT-2001-1001 · Openssh+1 · Openssh+5

Published

2001-04-17

·

Updated

2024-07-08

·

CVE-2001-0872

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions OpenSSH versions 3.0.1 and earlier openssh-server-2.9p2 openssh-clients-2.9p2 openssh-2.9p2 openssh-askpass-2.9p2 openssh-askpass-gnome-2.9p2 ssh-askpass-ptk
Description The issue concerns multiple vulnerabilities in OpenSSH and related packages, which can lead to breaches of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. Specifically, OpenSSH 3.0.1 and earlier with UseLogin enabled does not properly cleanse critical environment variables such as LD PRELOAD, allowing local users to gain root privileges.
Recommendations For OpenSSH versions 3.0.1 and earlier, consider disabling the UseLogin feature until a patch is available. For openssh-server-2.9p2, openssh-clients-2.9p2, openssh-2.9p2, openssh-askpass-2.9p2, and openssh-askpass-gnome-2.9p2, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For ssh-askpass-ptk, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALT-PU-2024-3921
ALT-PU-2024-4077
ALT-PU-2024-4467
ALT-PU-2024-9513
BDU:2015-01341
BDU:2015-08183
BDU:2015-08186
BDU:2015-08189
BDU:2015-08192
BDU:2015-08195
CVE-2001-0872

Affected Products

Alt Linux
Openssh
Openssh-Askpass
Openssh-Askpass-Gnome
Openssh-Clients
Openssh-Server