SSH Secure Shell for Servers and SSH Secure Shell for Workstations 2.0.13 through 3.2.1, when running without a PTY, does not call setsid to remove the child process from the process group of the parent process, which allows attackers to gain certain privileges.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ssh2 | Ssh | 2.0.13 (including) | 2.0.13 (including) |
Ssh2 | Ssh | 2.1 (including) | 2.1 (including) |
Ssh2 | Ssh | 2.2 (including) | 2.2 (including) |
Ssh2 | Ssh | 2.3 (including) | 2.3 (including) |
Ssh2 | Ssh | 2.4 (including) | 2.4 (including) |
Ssh2 | Ssh | 2.5 (including) | 2.5 (including) |
Ssh2 | Ssh | 3.0 (including) | 3.0 (including) |
Ssh2 | Ssh | 3.0.1 (including) | 3.0.1 (including) |
Ssh2 | Ssh | 3.1 (including) | 3.1 (including) |
Ssh2 | Ssh | 3.1.1 (including) | 3.1.1 (including) |
Ssh2 | Ssh | 3.1.2 (including) | 3.1.2 (including) |
Ssh2 | Ssh | 3.1.3 (including) | 3.1.3 (including) |
Ssh2 | Ssh | 3.1.4 (including) | 3.1.4 (including) |
Ssh2 | Ssh | 3.2 (including) | 3.2 (including) |
Ssh2 | Ssh | 3.2.1 (including) | 3.2.1 (including) |