PublicDateAtUSN: 2016-03-22 Candidate: CVE-2016-3115 PublicDate: 2016-03-22 10:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3115 http://www.openwall.com/lists/oss-security/2016/03/10/16 http://www.openssh.com/txt/x11fwd.adv https://ubuntu.com/security/notices/USN-2966-1 Description: Multiple CRLF injection vulnerabilities in session.c in sshd in OpenSSH before 7.2p2 allow remote authenticated users to bypass intended shell-command restrictions via crafted X11 forwarding data, related to the (1) do_authenticated1 and (2) session_x11_req functions. Ubuntu-Description: Notes: sbeattie> with X forwarding enabled, could bypass ssh account restrictions Bugs: Priority: low Discovered-by: Assigned-to: mdeslaur CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N [6.4 MEDIUM] Patches_openssh: upstream: https://anongit.mindrot.org/openssh.git/commit/?h=V_7_2&id=9d47b8d3f50c3a6282896df8274147e3b9a38c56 upstream_openssh: released (7.2p2) precise_openssh: released (1:5.9p1-5ubuntu1.9) precise/esm_openssh: released (1:5.9p1-5ubuntu1.9) trusty_openssh: released (1:6.6p1-2ubuntu2.7) trusty/esm_openssh: released (1:6.6p1-2ubuntu2.7) vivid/stable-phone-overlay_openssh: ignored (reached end-of-life) vivid/ubuntu-core_openssh: ignored (reached end-of-life) wily_openssh: released (1:6.9p1-2ubuntu0.2) xenial_openssh: not-affected (1:7.2p2-4) esm-infra/xenial_openssh: not-affected (1:7.2p2-4) yakkety_openssh: not-affected (1:7.2p2-5) zesty_openssh: not-affected (1:7.2p2-5) devel_openssh: not-affected (1:7.2p2-5)