LWN.net Logo

pam_ssh: privilege escalation

Package(s):pam_ssh CVE #(s):
Created:June 21, 2011 Updated:June 22, 2011
Description: From the Red Hat bugzilla:

It was found that pam_ssh, PAM module for use with SSH keys and ssh-agent, did not properly drop root SGID privileges prior executing the ssh-agent authentication agent. A local attacker could use this flaw to potentially escalate their privileges.

Alerts:
Fedora FEDORA-2011-8006 2011-06-08
Fedora FEDORA-2011-8036 2011-06-08
Fedora FEDORA-2011-8022 2011-06-08

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds