Back to search
CVE-2016-1908
Published: Apr 11, 2017
Modified: May 29, 2026
PUBLISHED
Description
The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-control decisions, which allows remote X11 clients to trigger a fallback and obtain trusted X11 forwarding privileges by leveraging configuration issues on this X11 server, as demonstrated by lack of the SECURITY extension on this X11 server.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
1034705
vdb-entry
RHSA-2016:0741
vendor-advisory
GLSA-201612-18
vendor-advisory
84427
vdb-entry
RHSA-2016:0465
vendor-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now