[openssh] [CVE-2008-1483] allows local users to hijack forwarded X connections
Bug #210175 reported by
disabled.user
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
openssh (Debian) |
Fix Released
|
Unknown
|
|||
openssh (Gentoo Linux) |
Fix Released
|
Medium
|
|||
openssh (Mandriva) |
Unknown
|
Unknown
|
|||
openssh (Ubuntu) |
Fix Released
|
Undecided
|
Unassigned | ||
Dapper |
Fix Released
|
Low
|
Kees Cook | ||
Edgy |
Fix Released
|
Low
|
Kees Cook | ||
Feisty |
Fix Released
|
Low
|
Kees Cook | ||
Gutsy |
Fix Released
|
Low
|
Kees Cook |
Bug Description
References:
MDVSA-2008:078 (http://
Quoting:
"OpenSSH allows local users to hijack forwarded X connections by causing
ssh to set DISPLAY to :10, even when another process is listening on
the associated port."
Changed in openssh: | |
assignee: | nobody → keescook |
importance: | Undecided → Low |
status: | Confirmed → In Progress |
assignee: | nobody → keescook |
importance: | Undecided → Low |
status: | Confirmed → In Progress |
assignee: | nobody → keescook |
importance: | Undecided → Low |
status: | Confirmed → In Progress |
assignee: | nobody → keescook |
importance: | Undecided → Low |
status: | Confirmed → In Progress |
Changed in openssh: | |
status: | Unknown → Confirmed |
Changed in openssh: | |
status: | Confirmed → Fix Released |
Changed in openssh: | |
status: | Unknown → Fix Released |
Changed in openssh (Gentoo Linux): | |
importance: | Unknown → Medium |
To post a comment you must log in.
CVE-2008-1483 (http:// nvd.nist. gov/nvd. cfm?cvename= CVE-2008- 1483):
OpenSSH 4.3p2, and probably other versions, allows local users to hijack
forwarded X connections by causing ssh to set DISPLAY to :10, even when
another process is listening on the associated port, as demonstrated by
opening TCP port 6010 (IPv4) and sniffing a cookie sent by Emacs.