CVE-2015-6565: High severity openssh vulnerability
Published Aug 24, 2015
·Updated
sshd in OpenSSH 6.8 and 6.9 uses world-writable permissions for TTY devices, which allows local users to cause a denial of service (terminal disruption) or possibly have unspecified other impact by writing to a device, as demonstrated by writing an escape sequence.
Affected Software
2 affected components
OpenBSD OpenSSH=6.8
OpenBSD OpenSSH=6.9
Event History
Aug 24, 2015
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-6565?
CVE-2015-6565 is considered a moderate severity vulnerability as it allows local users to disrupt terminal operations.
2
How do I fix CVE-2015-6565?
To fix CVE-2015-6565, update to OpenSSH version 7.0 or later where this vulnerability has been addressed.
3
Who is affected by CVE-2015-6565?
CVE-2015-6565 affects users running OpenSSH versions 6.8 and 6.9.
4
What type of attack can CVE-2015-6565 facilitate?
CVE-2015-6565 can facilitate denial of service attacks by allowing local users to write to TTY devices.
5
Is CVE-2015-6565 exploited remotely?
No, CVE-2015-6565 requires local access to the system to exploit the vulnerability.