0ea48ddd5e
> Subject: ignore PAM environment vars when UseLogin=yes > > If PAM is configured to read user-specified environment variables > and UseLogin=yes in sshd_config, then a hostile local user may > attack /bin/login via LD_PRELOAD or similar environment variables > set via PAM. > > CVE-2015-8325, found by Shayan Sadigh, via Colin Watson |
||
---|---|---|
.. | ||
files | ||
patches | ||
template |