cbcvebase.
CVE-2016-1908
published 2017-04-11

CVE-2016-1908: The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-control…

PriorityP262critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
13.74%
96.1th percentile
The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-control decisions, which allows remote X11 clients to trigger a fallback and obtain trusted X11 forwarding privileges by leveraging configuration issues on this X11 server, as demonstrated by lack of the SECURITY extension on this X11 server.

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianopenssh< openssh 1:7.2p1-1 (bookworm)openssh 1:7.2p1-1 (bookworm)
openbsdopenssh< 7.27.2
openbsdopenssh>= 0 < 1:7.2p1-11:7.2p1-1
openbsdopenssh>= 0 < 1:7.2p1-11:7.2p1-1
openbsdopenssh>= 0 < 1:7.2p1-11:7.2p1-1
openbsdopenssh>= 0 < 1:7.2p1-11:7.2p1-1
openbsdopenssh>= 0 < 1:6.6p1-2ubuntu2.71:6.6p1-2ubuntu2.7
oraclelinux
oraclelinux
paloaltopan-os
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus

Detection & IOCsextracted from sources · hover to see the quote

  • Detect SSH connections using untrusted X11 forwarding ('ssh -X') that may silently fall back to trusted X11 forwarding ('ssh -Y') behavior — monitor for X11 forwarding sessions where the SECURITY extension is absent on the local X server
  • Flag systems where the X server lacks the SECURITY extension AND has 'xhost +si:localuser:<user>' enabled — both conditions together enable exploitation of this fallback on RHEL 7 and current Fedora
  • Identify vulnerable OpenSSH client versions prior to 7.2; patch to 7.2p1-1 or later resolves the issue
  • ·Exploitation requires the local X server to lack the SECURITY extension (not compiled in by default for X.org since 2007) AND to have non-MIT-cookie authentication methods enabled (e.g. localuser auth); systems with the SECURITY extension present (e.g. RHEL 6 after RHSA-2013:1620) are not vulnerable to the fallback
  • ·PAN-OS applied code changes in response to CVE-2016-1908 but confirmed PAN-OS itself is not impacted by this issue

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.