---
cve: "CVE-2016-1908"
severity: "CRITICAL"
cvss: 9.8
epss: "13.7%"
vendor: "n/a"
kev: false
exploited: false
published: "2017-04-11 18:59:00"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-09-06T06:31:29+02:00"
---

# CVE-2016-1908

> 9.8 CRITICAL

## Beschreibung

The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-control decisions, which allows remote X11 clients to trigger a fallback and obtain trusted X11 forwarding privileges by leveraging configuration issues on this X11 server, as demonstrated by lack of the SECURITY extension on this X11 server.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Referenzen

- <http://www.openssh.com/txt/release-7.2>
- <http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html>
- <https://anongit.mindrot.org/openssh.git/commit/?id=ed4ce82dbfa8a3a3c8ea6fa0db113c71e234416c>
- <http://openwall.com/lists/oss-security/2016/01/15/13>
- <http://www.securitytracker.com/id/1034705>
- <http://rhn.redhat.com/errata/RHSA-2016-0741.html>
- <https://security.gentoo.org/glsa/201612-18>
- <https://bugzilla.redhat.com/show_bug.cgi?id=1298741>
- <https://lists.debian.org/debian-lts-announce/2018/09/msg00010.html>
- <http://www.securityfocus.com/bid/84427>
- <http://rhn.redhat.com/errata/RHSA-2016-0465.html>
- <https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2016-1908) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
