Описание
The x11_open_helper function in channels.c in ssh in OpenSSH before 6.9, when ForwardX11Trusted mode is not used, lacks a check of the refusal deadline for X connections, which makes it easier for remote attackers to bypass intended access restrictions via a connection outside of the permitted time window.
Релиз | Статус | Примечание |
---|---|---|
devel | released | 1:6.7p1-6ubuntu1 |
esm-infra-legacy/trusty | not-affected | 1:6.6p1-2ubuntu2.2 |
precise | released | 1:5.9p1-5ubuntu1.6 |
trusty | released | 1:6.6p1-2ubuntu2.2 |
trusty/esm | not-affected | 1:6.6p1-2ubuntu2.2 |
upstream | released | 6.9 |
utopic | ignored | end of life |
vivid | released | 1:6.7p1-5ubuntu1.2 |
vivid/stable-phone-overlay | ignored | end of life, was pending |
vivid/ubuntu-core | released | 1:6.7p1-5ubuntu1.2 |
Показывать по
EPSS
4.3 Medium
CVSS2
Связанные уязвимости
The x11_open_helper function in channels.c in ssh in OpenSSH before 6.9, when ForwardX11Trusted mode is not used, lacks a check of the refusal deadline for X connections, which makes it easier for remote attackers to bypass intended access restrictions via a connection outside of the permitted time window.
The x11_open_helper function in channels.c in ssh in OpenSSH before 6.9, when ForwardX11Trusted mode is not used, lacks a check of the refusal deadline for X connections, which makes it easier for remote attackers to bypass intended access restrictions via a connection outside of the permitted time window.
The x11_open_helper function in channels.c in ssh in OpenSSH before 6. ...
The x11_open_helper function in channels.c in ssh in OpenSSH before 6.9, when ForwardX11Trusted mode is not used, lacks a check of the refusal deadline for X connections, which makes it easier for remote attackers to bypass intended access restrictions via a connection outside of the permitted time window.
Уязвимость средства криптографической защиты OpenSSH, связанная с ошибками управления привилегиями, позволяющая нарушителю оказать воздействие на целостность защищаемой информации
EPSS
4.3 Medium
CVSS2