Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-1908

Опубликовано: 11 апр. 2017
Источник: ubuntu
Приоритет: low
EPSS Средний
CVSS2: 7.5
CVSS3: 9.8

Описание

The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-control decisions, which allows remote X11 clients to trigger a fallback and obtain trusted X11 forwarding privileges by leveraging configuration issues on this X11 server, as demonstrated by lack of the SECURITY extension on this X11 server.

РелизСтатусПримечание
devel

not-affected

1:7.2p2-5
esm-infra-legacy/trusty

released

1:6.6p1-2ubuntu2.7
esm-infra-legacy/xenial

not-affected

1:7.2p2-4
esm-infra/xenial

not-affected

1:7.2p2-4
precise

released

1:5.9p1-5ubuntu1.9
precise/esm

not-affected

1:5.9p1-5ubuntu1.9
trusty

released

1:6.6p1-2ubuntu2.7
trusty/esm

released

1:6.6p1-2ubuntu2.7
upstream

released

7.2
vivid

ignored

end of life

Показывать по

EPSS

Процентиль: 96%
0.13736
Средний

7.5 High

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

redhat
больше 10 лет назад

The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-control decisions, which allows remote X11 clients to trigger a fallback and obtain trusted X11 forwarding privileges by leveraging configuration issues on this X11 server, as demonstrated by lack of the SECURITY extension on this X11 server.

CVSS3: 9.8
nvd
больше 9 лет назад

The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-control decisions, which allows remote X11 clients to trigger a fallback and obtain trusted X11 forwarding privileges by leveraging configuration issues on this X11 server, as demonstrated by lack of the SECURITY extension on this X11 server.

CVSS3: 9.8
debian
больше 9 лет назад

The client in OpenSSH before 7.2 mishandles failed cookie generation f ...

CVSS3: 9.8
github
около 4 лет назад

The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-control decisions, which allows remote X11 clients to trigger a fallback and obtain trusted X11 forwarding privileges by leveraging configuration issues on this X11 server, as demonstrated by lack of the SECURITY extension on this X11 server.

fstec
больше 9 лет назад

Уязвимость клиента средства криптографической защиты OpenSSH, позволяющая нарушителю получить доверенные права при взаимодействии с X11-сервером

EPSS

Процентиль: 96%
0.13736
Средний

7.5 High

CVSS2

9.8 Critical

CVSS3