PT-2007-1056 · Openssh+3 · Openssh+3
Published
2007-09-12
·
Updated
2024-07-08
·
CVE-2007-4752
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
openssh versions prior to 4.7
openssh-askpass-gnome version 3.9p1
openssh-askpass version 3.9p1
openssh-server version 3.9p1
openssh-clients version 3.9p1
Description:
The issue concerns multiple vulnerabilities in the openssh package, which can lead to a breach of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. The problem arises from improper handling of untrusted cookies, allowing attackers to gain privileges by treating an X client as trusted.
Recommendations:
For openssh versions prior to 4.7, update to version 4.7 or later.
For openssh-askpass-gnome version 3.9p1, consider disabling the
openssh-askpass-gnome function until a patch is available.
For openssh-askpass version 3.9p1, restrict access to the openssh-askpass module to minimize the risk of exploitation.
For openssh-server version 3.9p1, avoid using the ssh protocol in the affected server until the issue is resolved.
For openssh-clients version 3.9p1, consider disabling the openssh-clients function until a patch is available.Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Hp-Ux
Openssh
Red Hat