CVE-2015-5352

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
03/08/2015
Last modified:
12/04/2025

Description

The x11_open_helper function in channels.c in ssh in OpenSSH before 6.9, when ForwardX11Trusted mode is not used, lacks a check of the refusal deadline for X connections, which makes it easier for remote attackers to bypass intended access restrictions via a connection outside of the permitted time window.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:* 6.8 (including)


References to Advisories, Solutions, and Tools