|
OpenSSH contains a flaw that may allow a malicious local attacker to execute arbitrary code on the system. The issue is triggered by a vulnerability in the UseLogin configuration option. If the UseLogin option is enabled, a local attacker can set the LD_PRELOAD or LD_LIBRARY_PATH environment variable to point to a maliciously created shared library file, which would be executed with superuser privileges when the login program is executed. This flaw may lead to a loss of Confidentiality, Integrity, and/or Availability.
|