CRITICAL · 9.8

CVE-2016-1908

The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-control decisions, which allows remote X11 clients to tr...

Vulnerability Description

The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-control decisions, which allows remote X11 clients to trigger a fallback and obtain trusted X11 forwarding privileges by leveraging configuration issues on this X11 server, as demonstrated by lack of the SECURITY extension on this X11 server.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
OpenbsdOpenssh< 7.2
DebianDebian Linux8.0
OracleLinux6
RedhatEnterprise Linux Desktop6.0
RedhatEnterprise Linux Eus7.2
RedhatEnterprise Linux Server6.0
RedhatEnterprise Linux Server Aus7.2
RedhatEnterprise Linux Server Tus7.2
RedhatEnterprise Linux Workstation6.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2016-1908?

CVE-2016-1908 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-control decisions, which allows remote X11 clients to tr...

How severe is CVE-2016-1908?

CVE-2016-1908 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2016-1908?

Check the references section above for vendor advisories and patch information. Affected products include: Openbsd Openssh, Debian Debian Linux, Oracle Linux, Redhat Enterprise Linux Desktop, Redhat Enterprise Linux Eus.