Summary
The remote host is missing an update to ssh
announced via advisory DSA 091-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20091-1
Insight
If the UseLogin feature is enabled in for ssh local users could pass environment variables (including variables like LD_PRELOAD) to the login process. This has been fixed by not copying the environment of UseLogin is enabled.
Please note that the default configuration for Debian does not have the UseLogin enabled.
This has been fixed in version 1:1.2.3-9.4.
Severity
Classification
-
CVE CVE-2001-0872 -
CVSS Base Score: 7.2
AV:L/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities