vendor:
OpenSSH
by:
Federico Bento
7,2
CVSS
HIGH
Privilege Escalation
264
CWE
Product Name: OpenSSH
Affected Version From: 6.8
Affected Version To: 6.9
Patch Exists: YES
Related CWE: CVE-2015-6565
CPE: a:openbsd:openssh:6.8
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux, Mac, Windows
2015
OpenSSH 6.8-6.9 local privilege escalation – CVE-2015-6565
OpenSSH 6.8-6.9 is vulnerable to a local privilege escalation vulnerability due to a race condition in the PTY allocation code. This vulnerability allows a local user to gain root privileges. The vulnerability was discovered by Jann Horn and was assigned CVE-2015-6565.
Mitigation:
Upgrade to OpenSSH version 7.0 or later.