sshd in OpenSSH 6.8 and 6.9 uses world-writable permissions for TTY devices, which allows local users to cause a denial of service (terminal disruption) or possibly have unspecified other impact by writing to a device, as demonstrated by writing an escape sequence.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openssh | Openbsd | 6.8 (including) | 6.8 (including) |
Openssh | Openbsd | 6.9 (including) | 6.9 (including) |
Openssh | Ubuntu | upstream | * |