CVE-2008-1483: Medium severity openssh vulnerability
OpenSSH 4.3p2, and probably other versions, allows local users to hijack forwarded X connections by causing ssh to set DISPLAY to :10, even when another process is listening on the associated port, as demonstrated by opening TCP port 6010 (IPv4) and sniffing a cookie sent by Emacs.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1483?
CVE-2008-1483 has a moderate severity rating due to the potential for local users to hijack X11 connections.
How do I fix CVE-2008-1483?
To fix CVE-2008-1483, upgrade OpenSSH to a version higher than 4.3p2 that addresses this vulnerability.
What are the affected versions for CVE-2008-1483?
The primary affected version for CVE-2008-1483 is OpenSSH 4.3p2.
Can CVE-2008-1483 be exploited remotely?
CVE-2008-1483 cannot be exploited remotely as it requires local access to the system.
What impact does CVE-2008-1483 have on system security?
CVE-2008-1483 can allow an unauthorized local user to hijack X connection sessions and potentially gain access to sensitive information.