CVE-2015-5352

Priority
Low
Description
The x11_open_helper function in channels.c in ssh in OpenSSH before 6.9,
when ForwardX11Trusted mode is not used, lacks a check of the refusal
deadline for X connections, which makes it easier for remote attackers to
bypass intended access restrictions via a connection outside of the
permitted time window.
References
Bugs
Assigned-to
mdeslaur
Package
Upstream:released (6.9)
Ubuntu 14.04 LTS (Trusty Tahr):released (1:6.6p1-2ubuntu2.2)
Patches:
Upstream:https://anongit.mindrot.org/openssh.git/commit/?h=V_6_9&id=1bf477d3cdf1a864646d59820878783d42357a1d
Upstream:https://github.com/openssh/openssh-portable/commit/1bf477d3cdf1a864646d59820878783d42357a1d
More Information

Updated: 2017-12-15 20:34:30 UTC (commit 13913)