SB2021041901 - Security restrictions bypass in OpenSSH



SB2021041901 - Security restrictions bypass in OpenSSH

Published: April 19, 2021

Security Bulletin ID SB2021041901
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Security restrictions bypass (CVE-ID: N/A)

The vulnerability allows a remote user to escalate privileges on the system.

The vulnerability exists due to application does not properly impose security restrictions, when LogVerbose keyword option is enabled with a set of options that activated logging for the low-privileged sandboxed sshd process. A remote user who can exploit the low-privileged process can escape the OpenSSH sendboxing and attack the high-level processes.

Successful exploitation of this vulnerability requires presence of security issue in the low-level process.


Remediation

Install update from vendor's website.