First published: Tue Jan 09 2001(Updated: )
OpenSSH SSH client before 2.3.0 does not properly disable X11 or agent forwarding, which could allow a malicious SSH server to gain access to the X11 display and sniff X11 events, or gain access to the ssh-agent.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenSSH | =2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-1169 is considered a high-severity vulnerability due to the risk of unauthorized access to the X11 display and potential data exposure.
To fix CVE-2000-1169, upgrade the OpenSSH client to version 2.3.0 or later, which properly disables X11 and agent forwarding.
The potential impacts of CVE-2000-1169 include unauthorized access to the X11 display and ssh-agent, allowing attackers to intercept sensitive information.
CVE-2000-1169 affects OpenSSH versions prior to 2.3.0, specifically version 2.2.
Using OpenSSH versions below 2.3.0 is not safe due to the vulnerabilities associated with CVE-2000-1169, and users should upgrade immediately.