OpenSSH contains a flaw that may allow an attacker to gain access to unauthorized privileges. The issue is triggered when an error occurs in the ChrootDirectory feature during the handling of hard links to setuid programs that utilize configuration files in the chroot directory. This may allow a local attacker to gain escalated privileges.
Classification
Location:
Local Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Solution:
Patch / RCS
Exploit:
Exploit Unknown
Disclosure:
Vendor Verified
Solution
It has been reported that this issue has been fixed. Upgrade to version 5.2p1-6.fc11, or higher, to address this vulnerability.