The do_setup_env function in session.c in sshd in OpenSSH through 7.2p2, when the UseLogin feature is enabled and PAM is configured to read .pam_environment files in user home directories, allows local users to gain privileges by triggering a crafted environment for the /bin/login program, as demonstrated by an LD_PRELOAD environment variable.
Metrics
Affected Vendors & Products
References
History
Fri, 22 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-1262 | |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-22T14:29:32.902Z
Reserved: 2015-11-24T00:00:00.000Z
Link: CVE-2015-8325
Updated: 2024-08-06T08:13:32.458Z
Status : Modified
Published: 2016-05-01T01:59:00.143
Modified: 2026-05-06T22:30:45.220
Link: CVE-2015-8325
OpenCVE Enrichment
No data.