PT-2007-1056 · Openssh+3 · Openssh+3

Published

2007-09-12

·

Updated

2024-07-08

·

CVE-2007-4752

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: openssh versions prior to 4.7 openssh-askpass-gnome version 3.9p1 openssh-askpass version 3.9p1 openssh-server version 3.9p1 openssh-clients version 3.9p1
Description: The issue concerns multiple vulnerabilities in the openssh package, which can lead to a breach of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. The problem arises from improper handling of untrusted cookies, allowing attackers to gain privileges by treating an X client as trusted.
Recommendations: For openssh versions prior to 4.7, update to version 4.7 or later. For openssh-askpass-gnome version 3.9p1, consider disabling the openssh-askpass-gnome function until a patch is available. For openssh-askpass version 3.9p1, restrict access to the openssh-askpass module to minimize the risk of exploitation. For openssh-server version 3.9p1, avoid using the ssh protocol in the affected server until the issue is resolved. For openssh-clients version 3.9p1, consider disabling the openssh-clients function until a patch is available.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-3921
ALT-PU-2024-4077
ALT-PU-2024-4467
ALT-PU-2024-9513
BDU:2015-06466
BDU:2015-06468
BDU:2015-06470
BDU:2015-06472
BDU:2015-06474
BDU:2015-08365
BDU:2015-08366
BDU:2015-08367
BDU:2015-08368
BDU:2015-08369
BDU:2015-09602
CVE-2007-4752
DSA-1576-1
HPSBUX02287
OPENSUSE-SU-2024:11124-1
RHSA-2008:0855
RHSA-2008_0855

Affected Products

Alt Linux
Hp-Ux
Openssh
Red Hat