Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-3234

Overview

Vulnerability Score 6.5 6.5
CVE Id CVE-2008-3234
Last Modified 08 Aug 2014 04:46:44
Published 18 Jul 2008 12:41:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication SINGLE_INSTANCE

CVE-2008-3234

Summary

sshd in OpenSSH 4 on Debian GNU/Linux, and the 20070303 OpenSSH snapshot, allows remote authenticated users to obtain access to arbitrary SELinux roles by appending a :/ (colon slash) sequence, followed by the role name, to the username.

Vulnerable Systems

Application

  • Openbsd Openssh 4.0

  • Openssh 4


References

XF - openssh-sshd-selinuxrole-unauth-access(44037)

BID - 30276

MILW0RM - 6094


Last Updated: 27 May 2016 10:51:59