LWN.net Logo

openssh: privilege escalation

Package(s):openssh CVE #(s):CVE-2009-2904
Created:September 30, 2009 Updated:March 30, 2010
Description: From the Red Hat alert: A Red Hat specific patch used in the openssh packages as shipped in Red Hat Enterprise Linux 5.4 (RHSA-2009:1287) loosened certain ownership requirements for directories used as arguments for the ChrootDirectory configuration options. A malicious user that also has or previously had non-chroot shell access to a system could possibly use this flaw to escalate their privileges and run commands as any system user. (CVE-2009-2904)
Alerts:
Fedora FEDORA-2010-5429 2010-03-30
Red Hat RHSA-2009:1470-01 2009-09-30
CentOS CESA-2009:1470 2009-10-30

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds