sshd in OpenSSH 6.8 and 6.9 uses world-writable permissions for TTY devices, which allows local users to cause a denial of service (terminal disruption) or possibly have unspecified other impact by writing to a device, as demonstrated by writing an escape sequence.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade openssh | Aug 30, 2017 | Aug 23, 2015 |
| Freebsd | — | Upgrade openssh-portableUpgrade FreeBSD | Dec 10, 2025 | Aug 21, 2015 |
| Gentoo Linux | — | Upgrade net-misc/openssh. | Oct 30, 2017 | Aug 23, 2015 |
| Openbsd Openssh | — | Upgrade to the latest version of OpenSSH | Aug 26, 2015 | Aug 24, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub