Severity: Unknown
Affected Package: openssh
Summary: Multiple sshd privileged monitor vulnerabilities
The privileged monitor process of sshd(8) contained multiple flaws: the username of an already-authenticated user could be overwritten by the unprivileged child process, and a use-after-free in the monitor could be deterministically triggered by a compromised unprivileged child. A related use-after-free in the session multiplexing code could result in unintended termination of the connection. These issues could aid an attacker who has compromised the unprivileged child in circumventing authentication controls.
No specific recommendations provided.
Aliases: CVE-2015-6563, CVE-2015-6564
Published: August 25, 2015
Last Modified: August 25, 2015