CVE-2015-5352: Medium severity openssh vulnerability
The x11openhelper function in channels.c in ssh in OpenSSH before 6.9, when ForwardX11Trusted mode is not used, lacks a check of the refusal deadline for X connections, which makes it easier for remote attackers to bypass intended access restrictions via a connection outside of the permitted time window.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5352?
CVE-2015-5352 is considered a medium severity vulnerability due to the potential for remote attackers to bypass access restrictions.
How do I fix CVE-2015-5352?
To fix CVE-2015-5352, upgrade your OpenSSH version to 6.9 or later.
What systems are affected by CVE-2015-5352?
CVE-2015-5352 affects OpenSSH versions prior to 6.9.
What does CVE-2015-5352 exploit?
CVE-2015-5352 exploits a lack of deadline checks for X connections in non-ForwardX11Trusted mode.
Can CVE-2015-5352 lead to unauthorized access?
Yes, CVE-2015-5352 can potentially allow remote attackers to establish unauthorized X connections.