CVE-2012-5536

medium
Published 2013-02-22 · Modified 2026-04-29
CVSS v3
CVSS v2
6.2
VIR risk
6.2

Description

A certain Red Hat build of the pam_ssh_agent_auth module on Red Hat Enterprise Linux (RHEL) 6 and Fedora Rawhide calls the glibc error function instead of the error function in the OpenSSH codebase, which allows local users to obtain sensitive information from process memory or possibly gain privileges via crafted use of an application that relies on this module, as demonstrated by su and sudo.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://pkgs.fedoraproject.org/cgit/openssh.git/commit/?id=4f4687ce8045418f678c323bb22c837f35d7b9fa

OS impact

OSVersionStatusFixed in
redhat rhel6.0affected

References

CWEs

CWE-20

Verify integrity in audit chain (admin only). AS-IS.