Vulnerability Details CVE-2015-8325
The do_setup_env function in session.c in sshd in OpenSSH through 7.2p2, when the UseLogin feature is enabled and PAM is configured to read .pam_environment files in user home directories, allows local users to gain privileges by triggering a crafted environment for the /bin/login program, as demonstrated by an LD_PRELOAD environment variable.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 29.2%
CVSS Severity
CVSS v3 Score 7.8
CVSS v2 Score 7.2
Products affected by CVE-2015-8325
-
cpe:2.3:a:openbsd:openssh:2.1.1
-
cpe:2.3:a:openbsd:openssh:2.5.1
-
cpe:2.3:a:openbsd:openssh:2.5.2
-
cpe:2.3:a:openbsd:openssh:2.9
-
cpe:2.3:a:openbsd:openssh:2.9.9
-
cpe:2.3:a:openbsd:openssh:3.6.1
-
cpe:2.3:a:openbsd:openssh:3.7.1
-
cpe:2.3:a:openbsd:openssh:4.3
-
cpe:2.3:a:openbsd:openssh:5.8
-
cpe:2.3:a:openbsd:openssh:6.2
-
cpe:2.3:a:openbsd:openssh:7.1
-
cpe:2.3:a:openbsd:openssh:7.2
-
cpe:2.3:o:canonical:ubuntu_core:15.04
-
cpe:2.3:o:canonical:ubuntu_linux:12.04
-
cpe:2.3:o:canonical:ubuntu_linux:14.04
-
cpe:2.3:o:canonical:ubuntu_linux:15.10
-
cpe:2.3:o:canonical:ubuntu_touch:15.04
-
cpe:2.3:o:debian:debian_linux:7.0
-
cpe:2.3:o:debian:debian_linux:8.0