CVE-2016-3115
OpenSSH 7.2p1 - (Authenticated) xauth Command Injection
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
Multiple CRLF injection vulnerabilities in session.c in sshd in OpenSSH before 7.2p2 allow remote authenticated users to bypass intended shell-command restrictions via crafted X11 forwarding data, related to the (1) do_authenticated1 and (2) session_x11_req functions.
Múltiples vulnerabilidades de inyección CRLF en session.c en sshd en OpenSSH en versiones anteriores a 7.2p2 permite a usuarios remotos autenticados eludir las restricciones de comandos de shell previstas a través del redireccionamiento de datos X11 manipulados, relacionadas con las funciones (1) do_authenticated1 y (2) session_x11_req.
It was discovered that the OpenSSH server did not sanitize data received in requests to enable X11 forwarding. An authenticated client with restricted SSH access could possibly use this flaw to bypass intended restrictions.
OpenSSH is OpenBSD's SSH protocol implementation. These packages include the core files necessary for both the OpenSSH client and server. It was discovered that the OpenSSH server did not sanitize data received in requests to enable X11 forwarding. An authenticated client with restricted SSH access could possibly use this flaw to bypass intended restrictions. An access flaw was discovered in OpenSSH; the OpenSSH client did not correctly handle failures to generate authentication cookies for untrusted X11 forwarding. A malicious or compromised remote X application could possibly use this flaw to establish a trusted connection to the local X server, even if only untrusted X11 forwarding was requested.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-03-10 CVE Reserved
- 2016-03-14 CVE Published
- 2016-03-15 First Exploit
- 2024-08-05 CVE Updated
- 2025-05-04 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-20: Improper Input Validation
CAPEC
References (28)
URL | Tag | Source |
---|---|---|
http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/session.c | X_refsource_confirm | |
http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/session.c.diff?r1=1.281&r2=1.282&f=h | X_refsource_confirm | |
http://packetstormsecurity.com/files/136234/OpenSSH-7.2p1-xauth-Command-Injection-Bypass.html | X_refsource_misc |
|
http://seclists.org/fulldisclosure/2016/Mar/46 | Mailing List |
|
http://seclists.org/fulldisclosure/2016/Mar/47 | Mailing List |
|
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html | X_refsource_confirm |
|
http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html | X_refsource_confirm |
|
http://www.securityfocus.com/bid/84314 | Vdb Entry | |
http://www.securitytracker.com/id/1035249 | Vdb Entry | |
https://bto.bluecoat.com/security-advisory/sa121 | X_refsource_confirm | |
https://github.com/tintinweb/pub/tree/master/pocs/cve-2016-3115 | X_refsource_misc | |
https://lists.debian.org/debian-lts-announce/2018/09/msg00010.html | Mailing List |
|
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/136234 | 2016-03-15 | |
https://www.exploit-db.com/exploits/39569 | 2024-08-05 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Openbsd Search vendor "Openbsd" | Openssh Search vendor "Openbsd" for product "Openssh" | <= 7.2 Search vendor "Openbsd" for product "Openssh" and version " <= 7.2" | p1 |
Affected
| ||||||
Oracle Search vendor "Oracle" | Vm Server Search vendor "Oracle" for product "Vm Server" | 3.2 Search vendor "Oracle" for product "Vm Server" and version "3.2" | - |
Affected
|