Beveiligingsadvies

CVE-2016-1908

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2017-04-11 00:00:00
Laatst bijgewerkt 2026-05-29 20:14:45
Toegewezen door redhat
CVSS-score 9.8
Status PUBLISHED

Beschrijving

The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-control decisions, which allows remote X11 clients to trigger a fallback and obtain trusted X11 forwarding privileges by leveraging configuration issues on this X11 server, as demonstrated by lack of the SECURITY extension on this X11 server.