PT-2001-2550 · Openssh+1 · Openssh+1

Published

2001-06-19

·

Updated

2024-07-08

·

CVE-2001-1459

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions OpenSSH versions 2.9 and earlier
Description The issue allows local users to bypass resource limits (rlimits) set in pam.d because OpenSSH does not initiate a Pluggable Authentication Module (PAM) session when commands are executed with no pty.
Recommendations For OpenSSH versions 2.9 and earlier, consider updating to a version that initiates a PAM session for all commands, including those executed with no pty, to enforce resource limits set in pam.d.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALT-PU-2024-3921
ALT-PU-2024-4077
ALT-PU-2024-4467
ALT-PU-2024-9513
CVE-2001-1459

Affected Products

Alt Linux
Openssh