The x11_open_helper function in channels.c in ssh in OpenSSH before 6.9, when ForwardX11Trusted mode is not used, lacks a check of the refusal deadline for X connections, which makes it easier for remote attackers to bypass intended access restrictions via a connection outside of the permitted time window.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openssh | Openbsd | * | 6.8 (including) |
Red Hat Enterprise Linux 6 | RedHat | openssh-0:5.3p1-117.el6 | * |
Openssh | Ubuntu | devel | * |
Openssh | Ubuntu | precise | * |
Openssh | Ubuntu | trusty | * |
Openssh | Ubuntu | upstream | * |
Openssh | Ubuntu | utopic | * |
Openssh | Ubuntu | vivid | * |
Openssh | Ubuntu | vivid/stable-phone-overlay | * |
Openssh | Ubuntu | vivid/ubuntu-core | * |