PublicDateAtUSN: 2017-01-04 Candidate: CVE-2016-10010 PublicDate: 2017-01-05 02:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10010 https://www.openssh.com/txt/release-7.4 http://www.openwall.com/lists/oss-security/2016/12/19/2 https://ubuntu.com/security/notices/USN-3538-1 Description: sshd in OpenSSH before 7.4, when privilege separation is not used, creates forwarded Unix-domain sockets as root, which might allow local users to gain privileges via unspecified vectors, related to serverloop.c. Ubuntu-Description: Notes: sbeattie> unix socket forwarding was introduced in openssh 6.7 mdeslaur> privilege separation is enabled in Debian/Ubuntu Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=848715 Priority: low Discovered-by: Jann Horn Assigned-to: mdeslaur CVSS: nvd: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H [7.0 HIGH] Patches_openssh: upstream: https://github.com/openssh/openssh-portable/commit/b737e4d7433577403a31cff6614f6a1b0b5e22f4 upstream: https://github.com/openssh/openssh-portable/commit/51045869fa084cdd016fdd721ea760417c0a3bf3 upstream_openssh: released (1:7.4p1-1) precise_openssh: not-affected (code not present) precise/esm_openssh: not-affected (code not present) trusty_openssh: not-affected (code not present) trusty/esm_openssh: not-affected (code not present) vivid/stable-phone-overlay_openssh: ignored (reached end-of-life) vivid/ubuntu-core_openssh: ignored (reached end-of-life) xenial_openssh: released (1:7.2p2-4ubuntu2.4) esm-infra/xenial_openssh: released (1:7.2p2-4ubuntu2.4) yakkety_openssh: ignored (reached end-of-life) zesty_openssh: not-affected (1:7.4p1-1) artful_openssh: not-affected (1:7.4p1-1) devel_openssh: not-affected (1:7.4p1-1)