OpenSSH 4.3p2, and probably other versions, allows local users to hijack forwarded X connections by causing ssh to set DISPLAY to :10, even when another process is listening on the associated port, as demonstrated by opening TCP port 6010 (IPv4) and sniffing a cookie sent by Emacs.
CVSS Details
- CVSS 3.1 Base Score: 6.2
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Openssh | — | Upgrade macOS to the latest versionApply OS X security update 2008-006 | Dec 16, 2011 | Mar 24, 2008 |
| Debian | — | Upgrade openssh | Jul 30, 2024 | Mar 24, 2008 |
| Gentoo Linux | — | Upgrade net-misc/openssh. | Oct 30, 2017 | Mar 24, 2008 |
| Ibm Aix | — | Apply the fix or workaround for ssh_advisory | Nov 30, 2017 | Mar 24, 2008 |
| Suse | — | Upgrade openssh-askpass-gnomeUpgrade openssh-helpersUpgrade openssh-openssl1Upgrade openssh-clientsUpgrade openssh-server-config-rootloginUpgrade openssh-cavsUpgrade openssh-openssl1-helpersUpgrade openssh-fipsUpgrade openssh-serverUpgrade openssh-askpassUpgrade opensshUpgrade openssh-common | Feb 17, 2015 | Jul 11, 2013 |
| Ubuntu | — | Upgrade openssh-client | Nov 8, 2024 | Mar 24, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub