CVE-2012-5536

A certain Red Hat build of the pam_ssh_agent_auth module on Red Hat Enterprise Linux (RHEL) 6 and Fedora Rawhide calls the glibc error function instead of the error function in the OpenSSH codebase, which allows local users to obtain sensitive information from process memory or possibly gain privileges via crafted use of an application that relies on this module, as demonstrated by su and sudo.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.2 UNKNOWN
LOCAL
HIGH
AV:L/AC:H/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 35%
Affected Products (NVD)
VendorProductVersion
fedora_projectfedora_release_rawhide
-
redhatenterprise_linux
6.0
𝑥
= Vulnerable software versions
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
openssh
RHEL 6
0:5.3p1-84.1.el6
fixed
openssh-askpass
RHEL 6
0:5.3p1-84.1.el6
fixed
openssh-clients
RHEL 6
0:5.3p1-84.1.el6
fixed
openssh-ldap
RHEL 6
0:5.3p1-84.1.el6
fixed
openssh-server
RHEL 6
0:5.3p1-84.1.el6
fixed
pam
RHEL 6
0:0.9.3-84.1.el6
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
openssh
Amazon Linux 1
0:5.3p1-84.20.amzn1
fixed
openssh-clients
Amazon Linux 1
0:5.3p1-84.20.amzn1
fixed
openssh-debuginfo
Amazon Linux 1
0:5.3p1-84.20.amzn1
fixed
openssh-ldap
Amazon Linux 1
0:5.3p1-84.20.amzn1
fixed
openssh-server
Amazon Linux 1
0:5.3p1-84.20.amzn1
fixed
pam_ssh_agent_auth
Amazon Linux 1
0:0.9.3-84.20.amzn1
fixed