CVE-2016-3115
OpenSSH 7.2p1 - (Authenticated) xauth Command Injection
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Multiple CRLF injection vulnerabilities in session.c in sshd in OpenSSH before 7.2p2 allow remote authenticated users to bypass intended shell-command restrictions via crafted X11 forwarding data, related to the (1) do_authenticated1 and (2) session_x11_req functions.
Múltiples vulnerabilidades de inyección CRLF en session.c en sshd en OpenSSH en versiones anteriores a 7.2p2 permite a usuarios remotos autenticados eludir las restricciones de comandos de shell previstas a través del redireccionamiento de datos X11 manipulados, relacionadas con las funciones (1) do_authenticated1 y (2) session_x11_req.
It was discovered that the OpenSSH server did not sanitize data received in requests to enable X11 forwarding. An authenticated client with restricted SSH access could possibly use this flaw to bypass intended restrictions.
OpenSSH versions 7.2p1 and below suffer from a command injection and /bin/false bypass vulnerability via xauth.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-03-10 CVE Reserved
- 2016-03-14 CVE Published
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2024-08-12 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-20: Improper Input Validation
CAPEC
References (27)
URL | Tag | Source |
---|---|---|
http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/session.c | X_refsource_confirm | |
http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/session.c.diff?r1=1.281&r2=1.282&f=h | X_refsource_confirm | |
http://packetstormsecurity.com/files/136234/OpenSSH-7.2p1-xauth-Command-Injection-Bypass.html | X_refsource_misc | |
http://seclists.org/fulldisclosure/2016/Mar/46 | Mailing List | |
http://seclists.org/fulldisclosure/2016/Mar/47 | Mailing List | |
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html | X_refsource_confirm | |
http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html | X_refsource_confirm | |
http://www.securityfocus.com/bid/84314 | Vdb Entry | |
http://www.securitytracker.com/id/1035249 | Vdb Entry | |
https://bto.bluecoat.com/security-advisory/sa121 | X_refsource_confirm | |
https://github.com/tintinweb/pub/tree/master/pocs/cve-2016-3115 | X_refsource_misc | |
https://lists.debian.org/debian-lts-announce/2018/09/msg00010.html | Mailing List |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/39569 | 2024-08-05 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Openbsd Search vendor "Openbsd" | Openssh Search vendor "Openbsd" for product "Openssh" | <= 7.2 Search vendor "Openbsd" for product "Openssh" and version " <= 7.2" | p1 |
Affected
| ||||||
Oracle Search vendor "Oracle" | Vm Server Search vendor "Oracle" for product "Vm Server" | 3.2 Search vendor "Oracle" for product "Vm Server" and version "3.2" | - |
Affected
|