vendor:
OpenSSH
by:
Kingcope
7.2
CVSS
HIGH
SELinux Privilege Elevation
264
CWE
Product Name: OpenSSH
Affected Version From: OpenSSH-SNAP-20070303.tar.gz
Affected Version To: N/A
Patch Exists: Yes
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Fedora/RHEL Linux, Windows, Linux, Mac
2008
Debian (maybe other derivates |KUDUBUTUNTU|) OpenSSH Remote -=Authenticated=- SELinux Privilege Elevation
This vulnerability allows an authenticated user to set arbitrary SELinux roles when OpenSSH is configured with --with-selinux. This is done by specifying the role in the username after a forward slash '/'. This is a bug jailed in some distros because of legacy code.
Mitigation:
Upgrade to the latest version of OpenSSH and ensure that the --with-selinux flag is not enabled.