Back

HIGH

openssh falls back to the trusted x11 cookie if generation of an untrusted cookie fails

Published Sep 12, 2007

Description

ssh in OpenSSH before 4.7 does not properly handle when an untrusted cookie cannot be created and uses a trusted X11 cookie instead, which allows attackers to violate intended policy and gain privileges by causing an X client to be treated as trusted.

Affected products

Remediation

Red Hat statement

This issue did not affect the OpenSSH packages as distributed with Red Hat Enterprise Linux 2.1 or 3, as they do not support Trusted X11 forwarding.

Metrics

References (34)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 12, 2007
Updated Aug 7, 2024
Reserved Sep 7, 2007
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Sep 4, 2007