Local root hole in openssh with UseLogin Yes

Anyone running openssh, providing users with shell access via ssh, with UseLogin Yes set in /etc/ssh/sshd_config (or /etc/sshd_config, or /usr/local/etc/sshd_config, depending upon layout) should immediately change that line to UseLogin No and send a HUP to sshd.

Details will follow, once announced.

 

 

 

 

Top