REDHAT-BUG-1328012: Medium severity openssh vulnerability
If PAM is configured to read user-specified environment variables and UseLogin=yes in sshdconfig, then a hostile local user may attack /bin/login via LDPRELOAD or similar environment variables set via PAM.
Upstream fix:
https://anongit.mindrot.org/openssh.git/commit/?id=85bdcd7c92fe7ff133bbc4e10a65c91810f88755
Debian advisory:
https://www.debian.org/security/2016/dsa-3550
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1328012?
The vulnerability REDHAT-BUG-1328012 is considered critical as it allows a hostile local user to exploit PAM configuration to compromise /bin/login.
How do I fix REDHAT-BUG-1328012?
To mitigate REDHAT-BUG-1328012, configure PAM to prevent user-specified environment variables or set UseLogin=no in the sshd_config.
Who is affected by REDHAT-BUG-1328012?
Systems using OpenSSH with PAM configured to read user-specified environment variables and with UseLogin=yes are vulnerable to REDHAT-BUG-1328012.
What versions of OpenSSH are impacted by REDHAT-BUG-1328012?
All versions of OpenSSH that allow PAM to read user-defined environment variables and have UseLogin set to yes are impacted by REDHAT-BUG-1328012.
Is there a patch available for REDHAT-BUG-1328012?
Yes, an upstream fix for REDHAT-BUG-1328012 has been implemented and can be found in the latest updates for affected OpenSSH packages.