Vulnerability Bulletins

DSA-3550 openssh - security update

   
Affected software Debian
 
Shayan Sadigh discovered a vulnerability in OpenSSH: If PAM support isenabled and the sshd PAM configuration is configured to read userspecifiedenvironment variables and the UseLogin option is enabled, alocal user may escalate her privileges to root.

More info:

https://www.debian.org/security/2016/dsa-3550