ubuntu · CVE-2016-1908

Quick triage

Priority: low Published: 2016-01-15 00:00:00 UTC Updated: 2025-08-25 21:55:45 UTC

View at Official ubuntu advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2016-1908 low priority: Ubuntu including 1 source packages (openssh), 8 status rows across 8 suites (precise, trusty, upstream, vivid, wily, xenial, yakkety, zesty): released 4, not-affected 3, ignored 1.

Description:

The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-control decisions, which allows remote X11 clients to trigger a fallback and obtain trusted X11 forwarding privileges by leveraging configuration issues on this X11 server, as demonstrated by lack of the SECURITY extension on this X11 server.

cvelogic Threat Intelligence