Bug 706386 - (CVE-2011-1410) VUL-1: CVE-2011-1410: openssh: X11 forwarding hijacking
(CVE-2011-1410)
VUL-1: CVE-2011-1410: openssh: X11 forwarding hijacking
Status: CONFIRMED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: General
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Hans Petter Jansson
Security Team bot
. maint:planned:update
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2011-07-18 08:41 UTC by Ludwig Nussel
Modified: 2022-01-06 14:39 UTC (History)
3 users (show)

See Also:
Found By: Other
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Ludwig Nussel 2011-07-18 08:41:27 UTC
Your friendly security team received the following report via security@suse.de.
Please respond ASAP.
This issue is not public yet, please keep any information about it inside SUSE.
Note that build.opensuse.org *cannot* be used to prepare embargoed updates.

Timo Juhani Lindfors found that local users could hijack forwarded X11 connections. To exploit this an attackers must kill the ssh connection while an X client is starting up and then bind to the same port as ssh used before.

CVE-2011-1410
Comment 10 Swamp Workflow Management 2012-06-13 14:53:03 UTC
The SWAMPID for this issue is 47840.
This issue was rated as low.
Please submit fixed packages until 2012-07-11.
When done, please reassign the bug to security-team@suse.de.
Patchinfo will be handled by security team.
Comment 11 Marcus Meissner 2012-11-20 10:13:04 UTC
any news?
Comment 12 Petr Cerny 2012-11-21 14:11:51 UTC
No, but it is still on my radar.
Comment 13 Thomas Biege 2015-02-07 08:57:46 UTC
Any news here or is this already fixed due to never versions of openssl on SLE11 and SLE12?
Comment 14 Thomas Biege 2015-02-07 08:58:18 UTC
(In reply to Thomas Biege from comment #13)
> Any news here or is this already fixed due to never versions of openssl on
> SLE11 and SLE12?

openssl = openssh