Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2007-4752

Опубликовано: 12 сент. 2007
Источник: debian
EPSS Низкий

Описание

ssh in OpenSSH before 4.7 does not properly handle when an untrusted cookie cannot be created and uses a trusted X11 cookie instead, which allows attackers to violate intended policy and gain privileges by causing an X client to be treated as trusted.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
opensshfixed1:4.7p1-1package
opensshno-dsaetchpackage
opensshno-dsasargepackage

Примечания

  • An exploit needs limited control over the machine running a

  • trusted X client, so this is only a slight privilege

  • escalation. The X Security extension is merely an afterthought

  • and is unlikely to provide strong security guarantees.

EPSS

Процентиль: 84%
0.02369
Низкий

Связанные уязвимости

ubuntu
почти 18 лет назад

ssh in OpenSSH before 4.7 does not properly handle when an untrusted cookie cannot be created and uses a trusted X11 cookie instead, which allows attackers to violate intended policy and gain privileges by causing an X client to be treated as trusted.

redhat
почти 18 лет назад

ssh in OpenSSH before 4.7 does not properly handle when an untrusted cookie cannot be created and uses a trusted X11 cookie instead, which allows attackers to violate intended policy and gain privileges by causing an X client to be treated as trusted.

nvd
почти 18 лет назад

ssh in OpenSSH before 4.7 does not properly handle when an untrusted cookie cannot be created and uses a trusted X11 cookie instead, which allows attackers to violate intended policy and gain privileges by causing an X client to be treated as trusted.

github
около 3 лет назад

ssh in OpenSSH before 4.7 does not properly handle when an untrusted cookie cannot be created and uses a trusted X11 cookie instead, which allows attackers to violate intended policy and gain privileges by causing an X client to be treated as trusted.

fstec
больше 17 лет назад

Уязвимость операционной системы Gentoo Linux, позволяющая удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 84%
0.02369
Низкий