Use-after free in OpenSSH - CVE-2015-6564

 

Use-after free in OpenSSH - CVE-2015-6564

Published: December 21, 2016 / Updated: July 9, 2019


Vulnerability identifier: #VU1482
CSH Severity: Low
CVSS v4: 9.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H]
CVE-ID: CVE-2015-6564
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a use after free error within the mm_answer_pam_free_ctx() function in monitor.c in sshd daemon on non-OpenBSD platforms. A local unprivileged user can send an unexpected early MONITOR_REQ_PAM_FREE_CTX request and gain root privileges on the system.


Affected software

OpenSSH
FlashSystem 840 9840-AE1 & 9843-AE1
FlashSystem 900 9840-AE2 and 9843-AE2
Amazon Linux AMI
Junos OS
Fedora
Dell Secure Connect Gateway
openssh (Alpine package)
openssh
IBM SAN Volume Controller
IBM Storwize V3500
IBM Storwize V3700
IBM Storwize V5000
IBM Storwize V7000

How to mitigate CVE-2015-6564

Install updates from vendor's website.

OpenSSH - update to 7.0p1
Dell Secure Connect Gateway - update to 5.14.00.10
openssh (Alpine package) - update to 6.4_p1-r4
Junos OS - addressed in versions 12.3X48-D55, 12.3R12-S13, 15.1F6-S12, 15.1X49-D100, 15.1R5-S4, 15.1R6-S1, 15.1R7, 16.1R3-S4, 16.1R4-S3, 16.1R5, 16.2R1-S4, 16.2R2, 17.1R1-S2, 17.1R2, 17.2R1
openssh - addressed in versions 6.6.1p1-16.fc21, 6.9p1-5.fc22, 7.0p1-1.fc23
IBM SAN Volume Controller - addressed in versions 7.6.1.5, 7.7.0.4, 7.7.1.2
IBM Storwize V3500 - addressed in versions 7.6.1.5, 7.7.0.4, 7.7.1.2
IBM Storwize V3700 - addressed in versions 7.6.1.5, 7.7.0.4, 7.7.1.2
IBM Storwize V5000 - addressed in versions 7.6.1.5, 7.7.0.4, 7.7.1.2
IBM Storwize V7000 - addressed in versions 7.6.1.5, 7.7.0.4, 7.7.1.2

External References

Related Security Bulletins