Lucene search

K
f5F5F5:K93532943
HistoryApr 27, 2016 - 12:00 a.m.

K93532943 : SSHD session.c vulnerability CVE-2016-3115

2016-04-2700:00:00
my.f5.com
28

AI Score

6.9

Confidence

High

EPSS

0.017

Percentile

87.9%

Security Advisory Description

Multiple CRLF injection vulnerabilities in session.c in sshd in OpenSSH before 7.2p2 allow remote authenticated users to bypass intended shell-command restrictions via crafted X11 forwarding data, related to the (1) do_authenticated1 and (2) session_x11_req functions. (CVE-2016-3115)
Impact
Remote users may have the ability to read arbitrary files by using the authenticated user’s privilege.