CVE-2001-1459: High severity OpenBSD OpenSSH vulnerability
Published Jun 19, 2001
·Updated
OpenSSH 2.9 and earlier does not initiate a Pluggable Authentication Module (PAM) session if commands are executed with no pty, which allows local users to bypass resource limits (rlimits) set in pam.d.
Affected Software
8 affected components
OpenBSD OpenSSH=2.1.1
OpenBSD OpenSSH=2.5.1
OpenBSD OpenSSH=2.2
OpenBSD OpenSSH=2.1
OpenBSD OpenSSH=2.9
OpenBSD OpenSSH=2.5.2
OpenBSD OpenSSH=2.3
OpenBSD OpenSSH=2.5
Event History
Jun 19, 2001
CVE Published
04:00 AM
Apr 21, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-1459?
CVE-2001-1459 is considered a moderate severity vulnerability.
2
How do I fix CVE-2001-1459?
To fix CVE-2001-1459, update to a version of OpenSSH that is later than 2.9.
3
Who is affected by CVE-2001-1459?
Local users of OpenSSH versions 2.1.1 through 2.9 are affected by CVE-2001-1459.
4
What type of vulnerability is CVE-2001-1459?
CVE-2001-1459 is a local privilege escalation vulnerability.
5
What impact does CVE-2001-1459 have on system security?
CVE-2001-1459 allows local users to bypass resource limits imposed by PAM, potentially destabilizing the system.