Do your applications use this vulnerable package?
Test your applications
Overview
sshd in OpenSSH 4 on Debian GNU/Linux, and the 20070303 OpenSSH snapshot, allows remote authenticated users to obtain access to arbitrary SELinux roles by appending a :/ (colon slash) sequence, followed by the role name, to the username.
References
CVSS Score
6.3
low severity
-
Attack VectorNetwork
-
Attack ComplexityLow
-
Privileges RequiredLow
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityLow
-
IntegrityLow
-
AvailabilityLow
- CVE
- CVE-2008-3234
- CWE
- CWE-264
- Snyk ID
- SNYK-DEBIAN10-OPENSSH-368833
- Disclosed
- 18 Jul, 2008
- Published
- 18 Jul, 2008