CVE-2015-6563

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
24/08/2015
Last modified:
12/04/2025

Description

The monitor component in sshd in OpenSSH before 7.0 on non-OpenBSD platforms accepts extraneous username data in MONITOR_REQ_PAM_INIT_CTX requests, which allows local users to conduct impersonation attacks by leveraging any SSH login access in conjunction with control of the sshd uid to send a crafted MONITOR_REQ_PWNAM request, related to monitor.c and monitor_wrap.c.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:* 6.9 (including)
cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* 10.11.0 (including)


References to Advisories, Solutions, and Tools