PublicDateAtUSN: 2015-08-02 Candidate: CVE-2015-5352 PublicDate: 2015-08-03 01:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5352 http://www.openwall.com/lists/oss-security/2015/07/01/7 https://thejh.net/written-stuff/openssh-6.8-xsecurity https://ubuntu.com/security/notices/USN-2710-1 Description: The x11_open_helper function in channels.c in ssh in OpenSSH before 6.9, when ForwardX11Trusted mode is not used, lacks a check of the refusal deadline for X connections, which makes it easier for remote attackers to bypass intended access restrictions via a connection outside of the permitted time window. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=790798 Priority: low Discovered-by: Jann Horn Assigned-to: mdeslaur CVSS: Patches_openssh: upstream: https://anongit.mindrot.org/openssh.git/commit/?h=V_6_9&id=1bf477d3cdf1a864646d59820878783d42357a1d upstream: https://github.com/openssh/openssh-portable/commit/1bf477d3cdf1a864646d59820878783d42357a1d upstream_openssh: released (6.9) precise_openssh: released (1:5.9p1-5ubuntu1.6) trusty_openssh: released (1:6.6p1-2ubuntu2.2) trusty/esm_openssh: released (1:6.6p1-2ubuntu2.2) utopic_openssh: ignored (reached end-of-life) vivid_openssh: released (1:6.7p1-5ubuntu1.2) devel_openssh: released (1:6.7p1-6ubuntu1) vivid/stable-phone-overlay_openssh: pending (1:6.7p1-5ubuntu1.2) vivid/ubuntu-core_openssh: released (1:6.7p1-5ubuntu1.2)