CVE Vulnerabilities

CVE-2000-0217

Published: Feb 24, 2000 | Modified: Sep 10, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.1 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The default configuration of SSH allows X forwarding, which could allow a remote attacker to control a client’s X sessions via a malicious xauth program.

Affected Software

Name Vendor Start Version End Version
Openssh Openbsd 1.2 1.2
Ssh Ssh 1.2.0 1.2.0
Ssh Ssh 1.2.1 1.2.1
Ssh Ssh 1.2.2 1.2.2
Ssh Ssh 1.2.3 1.2.3
Ssh Ssh 1.2.4 1.2.4
Ssh Ssh 1.2.5 1.2.5
Ssh Ssh 1.2.6 1.2.6
Ssh Ssh 1.2.7 1.2.7
Ssh Ssh 1.2.8 1.2.8
Ssh Ssh 1.2.9 1.2.9
Ssh Ssh 1.2.10 1.2.10
Ssh Ssh 1.2.11 1.2.11
Ssh Ssh 1.2.12 1.2.12
Ssh Ssh 1.2.13 1.2.13
Ssh Ssh 1.2.14 1.2.14
Ssh Ssh 1.2.15 1.2.15
Ssh Ssh 1.2.16 1.2.16
Ssh Ssh 1.2.17 1.2.17
Ssh Ssh 1.2.18 1.2.18
Ssh Ssh 1.2.19 1.2.19
Ssh Ssh 1.2.20 1.2.20
Ssh Ssh 1.2.21 1.2.21
Ssh Ssh 1.2.22 1.2.22
Ssh Ssh 1.2.23 1.2.23
Ssh Ssh 1.2.24 1.2.24
Ssh Ssh 1.2.25 1.2.25
Ssh Ssh 1.2.26 1.2.26
Ssh Ssh 1.2.27 1.2.27
Ssh Ssh 1.2.28 1.2.28
Ssh Ssh 1.2.29 1.2.29
Ssh Ssh 1.2.30 1.2.30
Ssh Ssh 1.2.31 1.2.31
Ssh2 Ssh 2.0 2.0
Ssh2 Ssh 2.0.1 2.0.1
Ssh2 Ssh 2.0.2 2.0.2
Ssh2 Ssh 2.0.3 2.0.3
Ssh2 Ssh 2.0.4 2.0.4
Ssh2 Ssh 2.0.5 2.0.5
Ssh2 Ssh 2.0.6 2.0.6
Ssh2 Ssh 2.0.7 2.0.7
Ssh2 Ssh 2.0.8 2.0.8
Ssh2 Ssh 2.0.9 2.0.9
Ssh2 Ssh 2.0.10 2.0.10
Ssh2 Ssh 2.0.11 2.0.11
Ssh2 Ssh 2.0.12 2.0.12

References