First published: Thu Jun 08 2000(Updated: )
OpenSSH does not properly drop privileges when the UseLogin option is enabled, which allows local users to execute arbitrary commands by providing the command to the ssh daemon.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenSSH | =1.2.3 | |
OpenSSH | =2.1 | |
OpenSSH | =1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2000-0525 is considered high due to its potential for local users to execute arbitrary commands.
To fix CVE-2000-0525, disable the UseLogin option in the OpenSSH configuration file.
CVE-2000-0525 affects OpenSSH versions 1.2, 1.2.3, and 2.1.
The potential impacts of CVE-2000-0525 include unauthorized command execution by local users.
CVE-2000-0525 is relevant for systems running vulnerable versions of OpenSSH that have the UseLogin option enabled.