CVE-2015-6565
OpenSSH 6.8 < 6.9 - 'PTY' Local Privilege Escalation
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
sshd in OpenSSH 6.8 and 6.9 uses world-writable permissions for TTY devices, which allows local users to cause a denial of service (terminal disruption) or possibly have unspecified other impact by writing to a device, as demonstrated by writing an escape sequence.
El fichero sshd en OpenSSH 6.8 and 6.9 fija permisos de lectura para cualquier usuario en dispositivos TTY, lo que posibilita a usuarios locales provocar denegación de servicio (desorganización de terminales) o tener un impacto inesperado al escribir sobre un dispositivo, como se demuestra escribiendo una secuencia de escape
Multiple potential security vulnerabilities have been identified with the Matrix Operating Environment on Windows and Linux that could be exploited remotely resulting in Denial of Service (DoS), Unauthorized Access, Execution of arbitrary code, Cross-site scripting (XSS), Disclosure of Sensitive Information, Code Execution, and locally resulting in Cross-site Request Forgery (CSRF). Revision 1 of this advisory.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-08-21 CVE Reserved
- 2015-08-24 CVE Published
- 2017-01-27 First Exploit
- 2024-08-06 CVE Updated
- 2025-07-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (12)
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/140757 | 2017-01-27 | |
https://www.exploit-db.com/exploits/41173 | 2024-08-06 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.openssh.com/txt/release-7.0 | 2022-12-13 | |
https://security.gentoo.org/glsa/201512-04 | 2022-12-13 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Openbsd Search vendor "Openbsd" | Openssh Search vendor "Openbsd" for product "Openssh" | 6.8 Search vendor "Openbsd" for product "Openssh" and version "6.8" | - |
Affected
| ||||||
Openbsd Search vendor "Openbsd" | Openssh Search vendor "Openbsd" for product "Openssh" | 6.9 Search vendor "Openbsd" for product "Openssh" and version "6.9" | - |
Affected
|