[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248038

 
 

909

 
 

194772

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2008-1483Date: (C)2008-03-24   (M)2024-02-16


OpenSSH 4.3p2, and probably other versions, allows local users to hijack forwarded X connections by causing ssh to set DISPLAY to :10, even when another process is listening on the associated port, as demonstrated by opening TCP port 6010 (IPv4) and sniffing a cookie sent by Emacs.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 6.9
Exploit Score: 3.4
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
SUNALERT-1019235
SECTRACK-1019707
http://www.securityfocus.com/archive/1/490054/100/0/threaded
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2008-1483
SUNALERT-237444
BID-28444
SECUNIA-29522
SECUNIA-29537
SECUNIA-29554
SECUNIA-29626
SECUNIA-29676
SECUNIA-29683
SECUNIA-29686
SECUNIA-29721
SECUNIA-29735
SECUNIA-29873
SECUNIA-29939
SECUNIA-30086
SECUNIA-30230
SECUNIA-30249
SECUNIA-30347
SECUNIA-30361
SECUNIA-31531
SECUNIA-31882
ADV-2008-0994
ADV-2008-1123
ADV-2008-1124
ADV-2008-1448
ADV-2008-1526
ADV-2008-1624
ADV-2008-1630
ADV-2008-2396
ADV-2008-2584
APPLE-SA-2008-09-15
DSA-1576
FreeBSD-SA-08:05
GLSA-200804-03
HPSBUX02337
MDVSA-2008:078
NetBSD-SA2008-005
SSA:2008-095-01
SUSE-SR:2008:009
TA08-260A
USN-597-1
http://www.globus.org/mail_archive/security-announce/2008/04/msg00000.html
http://aix.software.ibm.com/aix/efixes/security/ssh_advisory.asc
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=463011
http://sourceforge.net/project/shownotes.php?release_id=590180&group_id=69227
http://support.attachmate.com/techdocs/2374.html
http://support.avaya.com/elmodocs2/security/ASA-2008-205.htm
http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0120
https://issues.rpath.com/browse/RPL-2397
openssh-sshd-session-hijacking(41438)
oval:org.mitre.oval:def:6085

CPE    1
cpe:/a:openbsd:openssh:4.3p2
CWE    1
CWE-264
OVAL    5
oval:org.secpod.oval:def:1100055
oval:org.secpod.oval:def:89044926
oval:org.secpod.oval:def:301315
oval:org.mitre.oval:def:7978
...

© SecPod Technologies