OpenSSH PAM Session Evasion Vulnerability...

- AV AC AU C I A
发布: 2001-06-19
修订: 2025-04-13

When OpenSSH is used in an environment using PAM, it may be possible for local users to evade restrictions enforced by PAM modules (such as rlimits). A PAM session is not initiated by OpenSSH when commands are executed in an 'rsh' manner (no pty). Some systems may rely on PAM to implement system restrictions, such as resource limits on processes. This vulnerability may allow remote users to bypass these restrictions.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息