CVE-2013-4548

OpenSSH 6.2-6.3 - Privilege Escalation

Title source: llm
STIX 2.1

Description

The mm_newkeys_from_blob function in monitor_wrap.c in sshd in OpenSSH 6.2 and 6.3, when an AES-GCM cipher is used, does not properly initialize memory for a MAC context data structure, which allows remote authenticated users to bypass intended ForceCommand and login-shell restrictions via packet data that provides a crafted callback address.

References (5)

Core 5
Core References
Vendor Advisory x_refsource_confirm
http://www.openssh.com/txt/gcmrekey.adv
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2014-1
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141576985122836&w=2
Mailing List mailing-list x_refsource_mlist
http://openwall.com/lists/oss-security/2013/11/08/3

Scores

EPSS 0.0031
EPSS Percentile 53.9%

Details

CWE
CWE-264
Status published
Products (2)
openbsd/openssh 6.2
openbsd/openssh 6.3
Published Nov 08, 2013
Tracked Since Feb 18, 2026