Back to search
CVE-2015-8325
Published: May 1, 2016
Modified: May 22, 2026
PUBLISHED
Description
The do_setup_env function in session.c in sshd in OpenSSH through 7.2p2, when the UseLogin feature is enabled and PAM is configured to read .pam_environment files in user home directories, allows local users to gain privileges by triggering a crafted environment for the /bin/login program, as demonstrated by an LD_PRELOAD environment variable.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
86187
vdb-entry
DSA-3550
vendor-advisory
RHSA-2017:0641
vendor-advisory
RHSA-2016:2588
vendor-advisory
1036487
vdb-entry
GLSA-201612-18
vendor-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now