BSA-2016-015
Summary
Security Advisory ID : BSA-2016-015
Component : OpenSSH
Revision : 3.0: Final
The do_setup_env function in session.c in sshd in OpenSSH through 7.2p2, when the UseLogin feature is enabled and PAM is configured to read .pam_environment files in user home directories, allows local users to gain privileges by triggering a crafted environment for the /bin/login program, as demonstrated by an LD_PRELOAD environment variable.
Affected Products
No Brocade Fibre Channel technology products from Broadcom are currently known to be affected by this vulnerability.
Revision History
| Version | Change | Date |
|---|---|---|
| 1.0 | Initial Publication | May 10, 2016 |
| 2.0 | Updated with Fibre Channel Products Only | Sept 20, 2018 |
| 3.0 | Updated with Brocade Fabric OS final statement | May 24, 2019 |