CVE-2016-1908

The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-control decisions, which allows remote X11 clients to trigger a fallback and obtain trusted X11 forwarding privileges by leveraging configuration issues on ...

critical 9.8 CVSS 3.1
Published: Apr 11, 2017
Modified: May 29, 2026
Vendor: Openbsd
Product: Openssh
Versions: 8.0,6,7,6.0,7.0,7.2,7.3,7.4,7.5,7.6

Description

The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-control decisions, which allows remote X11 clients to trigger a fallback and obtain trusted X11 forwarding privileges by leveraging configuration issues on this X11 server, as demonstrated by lack of the SECURITY extension on this X11 server.

References

Related CVEs