CVE Database
/

CVE-2016-3115

Back to search

CVE-2016-3115

Published: Mar 22, 2016

Modified: May 29, 2026

PUBLISHED

Description

Multiple CRLF injection vulnerabilities in session.c in sshd in OpenSSH before 7.2p2 allow remote authenticated users to bypass intended shell-command restrictions via crafted X11 forwarding data, related to the (1) do_authenticated1 and (2) session_x11_req functions.

VendorProductVersions

n/a

n/a

affected
n/a

References

FreeBSD-SA-16:14
vendor-advisory
x_refsource_FREEBSD
39569
exploit
x_refsource_EXPLOIT-DB
RHSA-2016:0466
vendor-advisory
x_refsource_REDHAT
1035249
vdb-entry
x_refsource_SECTRACK
FEDORA-2016-fc1cc33e05
vendor-advisory
x_refsource_FEDORA
FEDORA-2016-d339d610c1
vendor-advisory
x_refsource_FEDORA
GLSA-201612-18
vendor-advisory
x_refsource_GENTOO
84314
vdb-entry
x_refsource_BID
FEDORA-2016-0bcab055a7
vendor-advisory
x_refsource_FEDORA
FEDORA-2016-08e5803496
vendor-advisory
x_refsource_FEDORA
RHSA-2016:0465
vendor-advisory
x_refsource_REDHAT
FEDORA-2016-188267b485
vendor-advisory
x_refsource_FEDORA
FEDORA-2016-bb59db3c86
vendor-advisory
x_refsource_FEDORA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2016-3115 - Security Vulnerability | QwikSec