MNBSD-2015-11: Multiple sshd privileged monitor vulnerabilities

Severity: Unknown

Affected Package: openssh

Summary: Multiple sshd privileged monitor vulnerabilities

Description

The privileged monitor process of sshd(8) contained multiple flaws: the username of an already-authenticated user could be overwritten by the unprivileged child process, and a use-after-free in the monitor could be deterministically triggered by a compromised unprivileged child. A related use-after-free in the session multiplexing code could result in unintended termination of the connection. These issues could aid an attacker who has compromised the unprivileged child in circumventing authentication controls.

Affected Versions

openssh

Recommendations

No specific recommendations provided.

References

Additional Information

Aliases: CVE-2015-6563, CVE-2015-6564

Published: August 25, 2015
Last Modified: August 25, 2015