OpenSSH 3.0.1 and earlier with UseLogin enabled does not properly cleanse critical environment variables such as LD_PRELOAD, which allows local users to gain root privileges.
Software | From | Fixed in |
---|---|---|
redhat / linux | 7.0 | 7.0.x |
redhat / linux | 7.1 | 7.1.x |
redhat / linux | 7.2 | 7.2.x |
suse / suse_linux | 6.4 | 6.4.x |
suse / suse_linux | 7.0 | 7.0.x |
suse / suse_linux | 7.1 | 7.1.x |
suse / suse_linux | 7.2 | 7.2.x |
suse / suse_linux | 7.3 | 7.3.x |
openbsd / openssh | - | 3.0.1.x |