CVE-2012-5536
Summary
| CVE | CVE-2012-5536 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-02-22 00:55:00 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | A certain Red Hat build of the pam_ssh_agent_auth module on Red Hat Enterprise Linux (RHEL) 6 and Fedora Rawhide calls the glibc error function instead of the error function in the OpenSSH codebase, which allows local users to obtain sensitive information from process memory or possibly gain privileges via crafted use of an application that relies on this module, as demonstrated by su and sudo. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
HighAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:H/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Fedora Project | Fedora Release Rawhide | - | All | All | All |
| Operating System | Redhat | Enterprise Linux | 6.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| 834618 – (CVE-2012-5536) CVE-2012-5536 pam_ssh_agent_auth: symbol crash leading to glibc error() called incorrectly | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| Page not found :'( - src.fedoraproject.org | af854a3a-2127-422b-91ae-364da2661108 | pkgs.fedoraproject.org | Exploit, Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.