CVE-2016-1908

The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-control decisions, which allows remote X11 clients to trigger a fallback and obtain trusted X11 forwarding privileges by leveraging configuration issues on this X11 server, as demonstrated by lack of the SECURITY extension on this X11 server.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openbsd:openssh:*:p2:*:*:*:*:*:*

Information

Published : 2017-04-11 18:59

Updated : 2018-09-11 10:29


NVD link : CVE-2016-1908

Mitre link : CVE-2016-1908


JSON object : View

Products Affected

openbsd

  • openssh
CWE
CWE-254

7PK - Security Features