PT-2008-1128 · Openbsd+4 · Openssh+4

Timo Juhani Lindfors

·

Publicado

2005-10-05

·

Atualizado

2024-07-08

·

CVE-2008-1483

CVSS v2.0

6.9

Média

VetorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenSSH versions prior to 4.7 p1-r6 OpenSSH version 4.3p2
Description The issue allows local users to hijack forwarded X connections by causing ssh to set DISPLAY to :10, even when another process is listening on the associated port. This can be demonstrated by opening TCP port 6010 (IPv4) and sniffing a cookie sent by Emacs. Exploitation of the vulnerabilities may lead to disruption of confidentiality, integrity, and availability of protected information.
Recommendations For OpenSSH versions prior to 4.7 p1-r6, update to version 4.7 p1-r6 or later to resolve the issue. For OpenSSH version 4.3p2, consider disabling the forwarding of X connections as a temporary workaround until a patch is available. Restrict access to the associated port to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2024-3921
ALT-PU-2024-4077
ALT-PU-2024-4467
ALT-PU-2024-9513
BDU:2015-09635
CVE-2008-1483
DSA-1576-1
HPSBUX02337
OPENSUSE-SU-2024:11124-1
RHSA-2005:527
RHSA-2005_527
SUSE-SU-2017:3230-1
SUSE-SU-2017_3230-1
SUSE-SU-2018:2275-1
SUSE-SU-2018:2685-1
SUSE-SU-2018:2719-1
SUSE-SU-2018_2275-1
SUSE-SU-2018_2685-1
SUSE-SU-2018_2719-1

Produtos afetados

Alt Linux
Hp-Ux
Openssh
Red Hat
Suse