Lucene search

K
cve[email protected]CVE-2008-1483
HistoryMar 24, 2008 - 11:44 p.m.

CVE-2008-1483

2008-03-2423:44:00
CWE-264
web.nvd.nist.gov
131
openssh
hijacking
x connections
security vulnerability
cve-2008-1483
nvd

6.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

5.8 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.7%

OpenSSH 4.3p2, and probably other versions, allows local users to hijack forwarded X connections by causing ssh to set DISPLAY to :10, even when another process is listening on the associated port, as demonstrated by opening TCP port 6010 (IPv4) and sniffing a cookie sent by Emacs.

Affected configurations

NVD
Node
openbsdopensshMatch4.3p2
CPENameOperatorVersion
openbsd:opensshopenbsd openssheq4.3p2

References

6.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

5.8 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.7%