First published: Mon Aug 24 2015(Updated: )
sshd in OpenSSH 6.8 and 6.9 uses world-writable permissions for TTY devices, which allows local users to cause a denial of service (terminal disruption) or possibly have unspecified other impact by writing to a device, as demonstrated by writing an escape sequence.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenSSH | =6.8 | |
OpenSSH | =6.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6565 is considered a moderate severity vulnerability as it allows local users to disrupt terminal operations.
To fix CVE-2015-6565, update to OpenSSH version 7.0 or later where this vulnerability has been addressed.
CVE-2015-6565 affects users running OpenSSH versions 6.8 and 6.9.
CVE-2015-6565 can facilitate denial of service attacks by allowing local users to write to TTY devices.
No, CVE-2015-6565 requires local access to the system to exploit the vulnerability.