peter bassill · operator
$ cve CVE-2016-1908 JSON

CVE-2016-1908

9.8
CRITICAL · CVSS 3.1 · EPSS 13.7% (pctl 96)

Patch early

EPSS 13.7% — above the 10% action threshold.

Description

The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-control decisions, which allows remote X11 clients to trigger a fallback and obtain trusted X11 forwarding privileges by leveraging configuration issues on this X11 server, as demonstrated by lack of the SECURITY extension on this X11 server.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS13.74% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-287
On CISA KEVno
Public exploitnone known
Published2017-04-11
Last modified2026-06-17

Affected (9)

VendorProduct
debiandebian linux
openbsdopenssh
oraclelinux
redhatenterprise linux desktop
redhatenterprise linux eus
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux server tus
redhatenterprise linux workstation

References

→ the Explorer  ·  watch your stack  ·  NVD