[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256040

 
 

909

 
 

199103

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2015-568 --- openssh, pam_ssh_agent_auth

ID: oval:org.secpod.oval:def:1200149Date: (C)2015-12-30   (M)2023-12-07
Class: PATCHFamily: unix




It was reported that when forwarding X11 connections with ForwardX11Trusted=no, connections made after ForwardX11Timeout expired could be permitted and no longer subject to XSECURITY restrictions because of an ineffective timeout check in ssh coupled with "fail open" behavior in the X11 server when clients attempted connections with expired credentials.

Platform:
Amazon Linux AMI
Product:
openssh
pam_ssh_agent_auth
Reference:
ALAS-2015-568
CVE-2015-5352
CVE    1
CVE-2015-5352
CPE    3
cpe:/o:amazon:linux
cpe:/a:openbsd:openssh:6.8
cpe:/a:openbsd:openssh

© SecPod Technologies