Sales Chat - Click Here

OpenSSH gain of privilege via unspecified vectors related to serverloop.c


Jun 28, 2023

Vulnerability in OpenSSH may allow gain of privilege via unspecified vectors, related to serverloop.c

Summary

This vulnerability applies to OpenSSH before 7.4 when privilege separation is not used. Buffalo units on these versions of Open SSH do have privilege separation enabled, and are thus not affected. Scanners frequently only scan the installed version of tools such as OpenSSH and may show a false positive. 

Vulnerability ID Vulnerability Overview
CVE-2016-10010 sshd in OpenSSH before 7.4, when privilege separation is not used, creates forwarded Unix-domain sockets as root, which might allow local users to gain privileges via unspecified vectors, related to serverloop.c.

Affected Supported TeraStations

None

Back to Security Notices

Date Description
6/28/2023 Initial release
X