Vulnerability Name: | CVE-2012-5536 (CCN-82231) | ||||||||||||||||
Assigned: | 2012-10-24 | ||||||||||||||||
Published: | 2013-02-21 | ||||||||||||||||
Updated: | 2019-04-22 | ||||||||||||||||
Summary: | A certain Red Hat build of the pam_ssh_agent_auth module on Red Hat Enterprise Linux (RHEL) 6 and Fedora Rawhide calls the glibc error function instead of the error function in the OpenSSH codebase, which allows local users to obtain sensitive information from process memory or possibly gain privileges via crafted use of an application that relies on this module, as demonstrated by su and sudo. | ||||||||||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||
CVSS v2 Severity: | 6.2 Medium (CVSS v2 Vector: AV:L/AC:H/Au:N/C:C/I:C/A:C) 4.6 Medium (Temporal CVSS v2 Vector: AV:L/AC:H/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
5.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
4.6 Medium (REDHAT Temporal CVSS v2 Vector: AV:L/AC:H/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||||||||||
Vulnerability Type: | CWE-20 | ||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2012-5536 Source: CONFIRM Type: Exploit, Patch http://pkgs.fedoraproject.org/cgit/openssh.git/commit/?id=4f4687ce8045418f678c323bb22c837f35d7b9fa Source: CCN Type: RHSA-2013-0519 Moderate: openssh security, bug fix and enhancement update Source: REDHAT Type: UNKNOWN RHSA-2013:0519 Source: CCN Type: BID-58097 'pam_ssh_agent_auth' Module CVE-2012-5536 Local Denial of Service Vulnerability Source: CCN Type: Red Hat Bugzilla Bug 834618 CVE-2012-5536 pam_ssh_agent_auth: symbol crash leading to glibc error() called incorrectly Source: CONFIRM Type: UNKNOWN https://bugzilla.redhat.com/show_bug.cgi?id=834618 Source: XF Type: UNKNOWN openssh-pamsshagentauth-code-exec(82231) | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Configuration RedHat 4: Configuration RedHat 5: Configuration CCN 1: ![]() | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |