CyberSec.Space Logo
CVEブラウザに戻る

CVE-2016-1908

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.1400%
EPSS Percentile34.52th
Published2017年4月11日
Last Modified2026年5月29日

Vulnerability Description

The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-control decisions, which allows remote X11 clients to trigger a fallback and obtain trusted X11 forwarding privileges by leveraging configuration issues on this X11 server, as demonstrated by lack of the SECURITY extension on this X11 server.

Affected Platforms (CPE)

📦
Openbsd

Openssh

< 7.2
💻
Debian

Debian Linux

= 8.0
💻
Oracle

Linux

= 6
💻
Oracle

Linux

= 7
💻
Redhat

Enterprise Linux Desktop

= 6.0
💻
Redhat

Enterprise Linux Desktop

= 7.0
💻
Redhat

Enterprise Linux Eus

= 7.2
💻
Redhat

Enterprise Linux Eus

= 7.3
💻
Redhat

Enterprise Linux Eus

= 7.4
💻
Redhat

Enterprise Linux Eus

= 7.5
💻
Redhat

Enterprise Linux Eus

= 7.6
💻
Redhat

Enterprise Linux Eus

= 7.7
💻
Redhat

Enterprise Linux Server

= 6.0
💻
Redhat

Enterprise Linux Server

= 7.0
💻
Redhat

Enterprise Linux Server Aus

= 7.2
💻
Redhat

Enterprise Linux Server Aus

= 7.3
💻
Redhat

Enterprise Linux Server Aus

= 7.4
💻
Redhat

Enterprise Linux Server Aus

= 7.6
💻
Redhat

Enterprise Linux Server Aus

= 7.7
💻
Redhat

Enterprise Linux Server Tus

= 7.2
💻
Redhat

Enterprise Linux Server Tus

= 7.3
💻
Redhat

Enterprise Linux Server Tus

= 7.6
💻
Redhat

Enterprise Linux Server Tus

= 7.7
💻
Redhat

Enterprise Linux Workstation

= 6.0
💻
Redhat

Enterprise Linux Workstation

= 7.0

References & Advisories

関連する脆弱性情報

CVE-2016-1908 Detail & Impact Analysis | CVSS 9.8 (CRITICAL) | Cyber-Sec.Space | Cyber-Sec.Space