Vulnerabilities > Fedora Project

DATE CVE VULNERABILITY TITLE RISK
2013-02-22 CVE-2012-5536 Improper Input Validation vulnerability in multiple products
A certain Red Hat build of the pam_ssh_agent_auth module on Red Hat Enterprise Linux (RHEL) 6 and Fedora Rawhide calls the glibc error function instead of the error function in the OpenSSH codebase, which allows local users to obtain sensitive information from process memory or possibly gain privileges via crafted use of an application that relies on this module, as demonstrated by su and sudo.
local
high complexity
fedora-project redhat CWE-20
6.2
2007-10-18 CVE-2007-3102 Remote Log Injection vulnerability in Openbsd Openssh 4.3P2
Unspecified vulnerability in the linux_audit_record_event function in OpenSSH 4.3p2, as used on Fedora Core 6 and possibly other systems, allows remote attackers to write arbitrary characters to an audit log via a crafted username.
4.3