CVE-2016-1908 vulnerability in OpenBSD and Other Products
Published on April 11, 2017
The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-control decisions, which allows remote X11 clients to trigger a fallback and obtain trusted X11 forwarding privileges by leveraging configuration issues on this X11 server, as demonstrated by lack of the SECURITY extension on this X11 server.
Products Associated with CVE-2016-1908
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2016-1908 are published in these products:
Exploit Probability
EPSS
0.93%
Percentile
75.84%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.