openssh: XSECURITY restrictions bypass under certain conditions in ssh(1)
Published Aug 3, 2015
4.3
MEDIUMCVSS 2.0
EPSS 5.45%
Description
The x11_open_helper function in channels.c in ssh in OpenSSH before 6.9, when ForwardX11Trusted mode is not used, lacks a check of the refusal deadline for X connections, which makes it easier for remote attackers to bypass intended access restrictions via a connection outside of the permitted time window.
Affected products
No data.
No data.
Red Hat Enterprise Linux 6
openssh-0:5.3p1-117.el6
Fixed · RHSA-2016:0741
Red Hat Enterprise Linux 5
openssh
Will not fix
Red Hat Enterprise Linux 7
openssh
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | openssh-0:5.3p1-117.el6 | Fixed | RHSA-2016:0741 |
| Red Hat Enterprise Linux 5 | openssh | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | openssh | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue does not affect the version of openssh package as shipped with Red Hat Enterprise Linux 7. This issue affects the version of openssh package as shipped with Red Hat Enterprise Linux 5 and 6. Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:N/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (47 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 5.45% (0.05445) | 92.48th | v5 (v2026.06.15) |
| Jun 15, 2026 | 5.42% (0.05420) | 91.65th | v5 (v2026.06.15) |
| Mar 4, 2026 | 5.39% (0.05390) | 89.93th | v4 (v2025.03.14) |
| Mar 1, 2026 | 7.85% (0.07847) | 91.88th | v4 (v2025.03.14) |
| Feb 4, 2026 | 5.02% (0.05019) | 89.45th | v4 (v2025.03.14) |
| Feb 1, 2026 | 7.32% (0.07324) | 91.51th | v4 (v2025.03.14) |
| Jan 4, 2026 | 5.02% (0.05019) | 89.39th | v4 (v2025.03.14) |
| Jan 1, 2026 | 7.32% (0.07324) | 91.45th | v4 (v2025.03.14) |
| Dec 27, 2025 | 4.13% (0.04133) | 88.33th | v4 (v2025.03.14) |
| Dec 14, 2025 | 5.39% (0.05394) | 89.78th | v4 (v2025.03.14) |
| Dec 7, 2025 | 3.51% (0.03507) | 87.18th | v4 (v2025.03.14) |
| Dec 4, 2025 | 5.15% (0.05153) | 89.47th | v4 (v2025.03.14) |
| Dec 1, 2025 | 7.30% (0.07298) | 91.35th | v4 (v2025.03.14) |
| Nov 4, 2025 | 5.15% (0.05153) | 89.39th | v4 (v2025.03.14) |
| Nov 1, 2025 | 7.30% (0.07298) | 91.28th | v4 (v2025.03.14) |
| Oct 4, 2025 | 5.15% (0.05153) | 89.43th | v4 (v2025.03.14) |
| Oct 1, 2025 | 7.30% (0.07298) | 91.34th | v4 (v2025.03.14) |
| Sep 7, 2025 | 5.49% (0.05487) | 89.85th | v4 (v2025.03.14) |
| Sep 1, 2025 | 7.03% (0.07031) | 91.17th | v4 (v2025.03.14) |
| Aug 4, 2025 | 5.49% (0.05487) | 89.84th | v4 (v2025.03.14) |
| Aug 1, 2025 | 7.03% (0.07031) | 91.15th | v4 (v2025.03.14) |
| Jul 5, 2025 | 5.15% (0.05153) | 89.40th | v4 (v2025.03.14) |
| Jul 1, 2025 | 7.30% (0.07298) | 91.24th | v4 (v2025.03.14) |
| Jun 19, 2025 | 5.15% (0.05153) | 89.38th | v4 (v2025.03.14) |
| Jun 5, 2025 | 8.90% (0.08896) | 92.09th | v4 (v2025.03.14) |
| Jun 1, 2025 | 12.35% (0.12345) | 93.55th | v4 (v2025.03.14) |
| May 24, 2025 | 8.90% (0.08896) | 92.09th | v4 (v2025.03.14) |
| May 5, 2025 | 10.17% (0.10169) | 92.68th | v4 (v2025.03.14) |
| May 1, 2025 | 14.02% (0.14016) | 93.97th | v4 (v2025.03.14) |
| Apr 19, 2025 | 10.17% (0.10169) | 92.66th | v4 (v2025.03.14) |
| Apr 18, 2025 | 14.02% (0.14016) | 93.91th | v4 (v2025.03.14) |
| Apr 14, 2025 | 10.17% (0.10169) | 92.40th | v4 (v2025.03.14) |
| Apr 13, 2025 | 14.02% (0.14016) | 93.75th | v4 (v2025.03.14) |
| Apr 10, 2025 | 10.17% (0.10169) | 92.41th | v4 (v2025.03.14) |
| Apr 9, 2025 | 14.02% (0.14016) | 93.76th | v4 (v2025.03.14) |
| Mar 30, 2025 | 10.17% (0.10169) | 92.39th | v4 (v2025.03.14) |
| Mar 29, 2025 | 15.69% (0.15689) | 91.22th | v4 (v2025.03.14) |
| Mar 28, 2025 | 10.17% (0.10169) | 92.39th | v4 (v2025.03.14) |
| Mar 27, 2025 | 14.02% (0.14016) | 93.37th | v4 (v2025.03.14) |
| Mar 17, 2025 | 10.17% (0.10169) | 92.54th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.87% (0.00874) | 83.14th | v3 (v2023.03.01) |
| May 23, 2024 | 0.87% (0.00874) | 82.43th | v3 (v2023.03.01) |
| May 3, 2024 | 1.24% (0.01236) | 85.34th | v3 (v2023.03.01) |
| Mar 7, 2023 | 1.24% (0.01236) | 83.29th | v3 (v2023.03.01) |
| Mar 6, 2023 | 3.78% (0.03779) | 85.48th | v2 (v2022.01.01) |
| Apr 1, 2022 | 3.78% (0.03779) | 84.01th | v2 (v2022.01.01) |
| Feb 4, 2022 | 3.78% (0.03779) | 67.21th | v2 (v2022.01.01) |
References (20)
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00017.html vendor-advisory
- http://openwall.com/lists/oss-security/2015/07/01/10 mailing-list
- http://rhn.redhat.com/errata/RHSA-2016-0741.html vendor-advisory
- http://www.openssh.com/txt/release-6.9 Vendor Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- http://www.securityfocus.com/bid/75525 vdb-entry
- http://www.securitytracker.com/id/1032797 vdb-entry
- http://www.ubuntu.com/usn/USN-2710-1 vendor-advisory
- http://www.ubuntu.com/usn/USN-2710-2 vendor-advisory
- https://access.redhat.com/security/cve/CVE-2015-5352 Vendor Advisory
- https://anongit.mindrot.org/openssh.git/commit/?h=V_6_9&id=1bf477d3cdf1a864646d59820878783d42357a1d
- https://bugzilla.redhat.com/show_bug.cgi?id=1238231 Issue Tracking
- https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf
- https://lists.debian.org/debian-lts-announce/2018/09/msg00010.html mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2015-5352
- https://security.gentoo.org/glsa/201512-04 vendor-advisory
- https://security.netapp.com/advisory/ntap-20181023-0001/
- https://thejh.net/written-stuff/openssh-6.8-xsecurity
- https://www.cve.org/CVERecord?id=CVE-2015-5352
Change history (0)
No recorded changes yet.