Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 146377 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.117696
Kategorie:Privilege escalation
Titel:OpenSSH 6.2 <= 8.7 Privilege Escalation Vulnerability
Zusammenfassung:OpenSSH is prone to a privilege scalation vulnerability in; certain configurations.
Beschreibung:Summary:
OpenSSH is prone to a privilege scalation vulnerability in
certain configurations.

Vulnerability Insight:
sshd failed to correctly initialise supplemental groups when
executing an AuthorizedKeysCommand or AuthorizedPrincipalsCommand, where a
AuthorizedKeysCommandUser or AuthorizedPrincipalsCommandUser directive has been set to run the
command as a different user. Instead these commands would inherit the groups that sshd was started
with.

Depending on system configuration, inherited groups may allow
AuthorizedKeysCommand/AuthorizedPrincipalsCommand helper programs to gain unintended privilege.

Neither AuthorizedKeysCommand nor AuthorizedPrincipalsCommand are enabled by default in
sshd_config.

Affected Software/OS:
OpenSSH versions 6.2 through 8.7.

Solution:
Update to version 8.8 or later.

CVSS Score:
4.4

CVSS Vector:
AV:L/AC:M/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2021-41617
https://bugzilla.suse.com/show_bug.cgi?id=1190975
https://security.netapp.com/advisory/ntap-20211014-0004/
Debian Security Information: DSA-5586 (Google Search)
https://www.debian.org/security/2023/dsa-5586
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6XJIONMHMKZDTMH6BQR5TNLF2WDCGWED/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W44V2PFQH5YLRN6ZJTVRKAD7CU6CYYET/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KVI7RWM2JLNMWTOFK6BDUSGNOIPZYPUT/
https://www.starwindsoftware.com/security/sw-20220805-0001/
https://www.tenable.com/plugins/nessus/154174
https://www.openssh.com/security.html
https://www.openssh.com/txt/release-8.8
https://www.openwall.com/lists/oss-security/2021/09/26/1
https://www.oracle.com/security-alerts/cpuapr2022.html
https://www.oracle.com/security-alerts/cpujul2022.html
https://lists.debian.org/debian-lts-announce/2023/12/msg00017.html
CopyrightCopyright (C) 2021 Greenbone Networks GmbH

Dies ist nur einer von 146377 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.