Back to search
CVE-2015-6563
Published: Aug 24, 2015
Modified: May 27, 2026
PUBLISHED
Description
The monitor component in sshd in OpenSSH before 7.0 on non-OpenBSD platforms accepts extraneous username data in MONITOR_REQ_PAM_INIT_CTX requests, which allows local users to conduct impersonation attacks by leveraging any SSH login access in conjunction with control of the sshd uid to send a crafted MONITOR_REQ_PWNAM request, related to monitor.c and monitor_wrap.c.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
FEDORA-2015-13469
vendor-advisory
APPLE-SA-2015-10-21-4
vendor-advisory
76317
vdb-entry
GLSA-201512-04
vendor-advisory
RHSA-2016:0741
vendor-advisory
SUSE-SU-2015:1581
vendor-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now