CVE-2015-8325
The do_setup_env function in session.c in sshd in OpenSSH through 7.2p2, when the UseLogin feature is enabled and PAM is configured to read .pam_environment files in user home directories, allows local users to gain privileges by triggering a crafted environment for the /bin/login program, as demonstrated by an LD_PRELOAD environment variable.
- Debian Debian Linux
- = 7.0, 8.0
- Fix
- Available
- CVSS 3.0
- 7.8 HIGH
- EPSS
- 0.6% (45th percentile)
- Weakness
- CWE-264, CWE-1262
- NVD status
- Modified
- Published
- 2016-05-01
CVE-2015-8325 at NVD
No indexed exploits for CVE-2015-8325 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2015-8325 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.