Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-1908

Опубликовано: 11 апр. 2017
Источник: ubuntu
Приоритет: low
CVSS2: 7.5
CVSS3: 9.8

Описание

The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-control decisions, which allows remote X11 clients to trigger a fallback and obtain trusted X11 forwarding privileges by leveraging configuration issues on this X11 server, as demonstrated by lack of the SECURITY extension on this X11 server.

РелизСтатусПримечание
devel

not-affected

1:7.2p2-5
esm-infra-legacy/trusty

released

1:6.6p1-2ubuntu2.7
esm-infra/xenial

not-affected

1:7.2p2-4
precise

released

1:5.9p1-5ubuntu1.9
precise/esm

not-affected

1:5.9p1-5ubuntu1.9
trusty

released

1:6.6p1-2ubuntu2.7
trusty/esm

released

1:6.6p1-2ubuntu2.7
upstream

released

7.2
vivid

ignored

end of life
vivid/stable-phone-overlay

ignored

end of life

Показывать по

7.5 High

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

redhat
почти 10 лет назад

The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-control decisions, which allows remote X11 clients to trigger a fallback and obtain trusted X11 forwarding privileges by leveraging configuration issues on this X11 server, as demonstrated by lack of the SECURITY extension on this X11 server.

CVSS3: 9.8
nvd
больше 8 лет назад

The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-control decisions, which allows remote X11 clients to trigger a fallback and obtain trusted X11 forwarding privileges by leveraging configuration issues on this X11 server, as demonstrated by lack of the SECURITY extension on this X11 server.

CVSS3: 9.8
debian
больше 8 лет назад

The client in OpenSSH before 7.2 mishandles failed cookie generation f ...

CVSS3: 9.8
github
больше 3 лет назад

The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-control decisions, which allows remote X11 clients to trigger a fallback and obtain trusted X11 forwarding privileges by leveraging configuration issues on this X11 server, as demonstrated by lack of the SECURITY extension on this X11 server.

fstec
больше 8 лет назад

Уязвимость клиента средства криптографической защиты OpenSSH, позволяющая нарушителю получить доверенные права при взаимодействии с X11-сервером

7.5 High

CVSS2

9.8 Critical

CVSS3