First published: Mon Mar 24 2008(Updated: )
OpenSSH 4.3p2, and probably other versions, allows local users to hijack forwarded X connections by causing ssh to set DISPLAY to :10, even when another process is listening on the associated port, as demonstrated by opening TCP port 6010 (IPv4) and sniffing a cookie sent by Emacs.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Fedora OpenSSH | =4.3p2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.