OpenBSD Security update Fixes OpenSSH Information Disclosure

OpenBSD Security update Fixes OpenSSH Information Disclosure

CVE ID : CVE-2008-1483Rated as : Low Risk Remotely Exploitable : NoLocally Exploitable : YesRelease Date : 2008-04-03

A weakness has been identified in Ubuntu, which could be exploited by local attackers to gain knowledge of sensitive information. This issue is caused by an error in OpenSSH. For additional information, see : FrSIRT/ADV-2008-0994 ChangeLog2008-04-03 : Initial release

***********   Title : OpenSSH Forwarded X Connection Information Disclosure VulnerabilityAdvisory ID : FrSIRT/ADV-2008-0994CVE ID : CVE-2008-1483Rated as : Low Risk Remotely Exploitable : NoLocally Exploitable : YesRelease Date : 2008-03-26   A weakness has been identified in OpenSSH, which could be exploited by local attackers to gain knowledge of sensitive information. This issue is caused by an error when binding and using TCP ports on the IPv6/IPv4 interfaces while another process is listening on the associated port, which could be exploited by malicious users to hijack forwarded X connections.CreditsVulnerability reported by Timo Juhani Lindfors.

Döküman Arama

Başlık :

Kapat