Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.105581
Categoría:General
Título:OpenSSH <= 7.2p1 Xauth Command Injection Vulnerability
Resumen:OpenSSH is prone to an xauth command injection vulnerability.
Descripción:Summary:
OpenSSH is prone to an xauth command injection vulnerability.

Vulnerability Insight:
An authenticated user may inject arbitrary xauth commands by
sending an x11 channel request that includes a newline character in the x11 cookie. The newline
acts as a command separator to the xauth binary. This attack requires the server to have
'X11Forwarding yes' enabled. Disabling it, mitigates this vector.

Vulnerability Impact:
By injecting xauth commands one gains limited* read/write
arbitrary files, information leakage or xauth-connect capabilities.

Affected Software/OS:
OpenSSH versions before 7.2p2.

Solution:
Update to version 7.2p2 or later.

CVSS Score:
5.5

CVSS Vector:
AV:N/AC:L/Au:S/C:P/I:P/A:N

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2016-3115
BugTraq ID: 84314
http://www.securityfocus.com/bid/84314
https://www.exploit-db.com/exploits/39569/
http://lists.fedoraproject.org/pipermail/package-announce/2016-May/184264.html
http://lists.fedoraproject.org/pipermail/package-announce/2016-March/179924.html
http://lists.fedoraproject.org/pipermail/package-announce/2016-April/183122.html
http://lists.fedoraproject.org/pipermail/package-announce/2016-March/178838.html
http://lists.fedoraproject.org/pipermail/package-announce/2016-March/180491.html
http://lists.fedoraproject.org/pipermail/package-announce/2016-April/183101.html
FreeBSD Security Advisory: FreeBSD-SA-16:14
https://www.freebsd.org/security/advisories/FreeBSD-SA-16:14.openssh.asc
http://seclists.org/fulldisclosure/2016/Mar/46
http://seclists.org/fulldisclosure/2016/Mar/47
https://security.gentoo.org/glsa/201612-18
http://packetstormsecurity.com/files/136234/OpenSSH-7.2p1-xauth-Command-Injection-Bypass.html
https://github.com/tintinweb/pub/tree/master/pocs/cve-2016-3115
https://lists.debian.org/debian-lts-announce/2018/09/msg00010.html
RedHat Security Advisories: RHSA-2016:0465
http://rhn.redhat.com/errata/RHSA-2016-0465.html
RedHat Security Advisories: RHSA-2016:0466
http://rhn.redhat.com/errata/RHSA-2016-0466.html
http://www.securitytracker.com/id/1035249
CopyrightCopyright (C) 2016 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.