CVE-2007-4752
Summary
| CVE | CVE-2007-4752 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-09-12 01:17:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | ssh in OpenSSH before 4.7 does not properly handle when an untrusted cookie cannot be created and uses a trusted X11 cookie instead, which allows attackers to violate intended policy and gain privileges by causing an X client to be treated as trusted. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Openbsd | Openssh | 4.0 | All | All | All |
| Application | Openbsd | Openssh | 4.0p1 | All | All | All |
| Application | Openbsd | Openssh | 4.1 | All | All | All |
| Application | Openbsd | Openssh | 4.1p1 | All | All | All |
| Application | Openbsd | Openssh | 4.2 | All | All | All |
| Application | Openbsd | Openssh | 4.2p1 | All | All | All |
| Application | Openbsd | Openssh | 4.3 | All | All | All |
| Application | Openbsd | Openssh | 4.3p1 | All | All | All |
| Application | Openbsd | Openssh | 4.3p2 | All | All | All |
| Application | Openbsd | Openssh | 4.4 | All | All | All |
| Application | Openbsd | Openssh | 4.4p1 | All | All | All |
| Application | Openbsd | Openssh | 4.5 | All | All | All |
| Application | Openbsd | Openssh | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Red Hat Update for Tampered OpenSSH Packages - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| OpenSSH X11 Cookie Local Authentication Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Bug 280471 – openssh falls back to the trusted x11 cookie if generation of an untrusted cookie fails [FC6] | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| [#RPL-1706] openssh uses a trusted X11cookie if creation of an untrusted cookie fails CVE-2007-4752 - rPath Issue Tracking System | af854a3a-2127-422b-91ae-364da2661108 | issues.rpath.com | Patch |
| SecurityReason - OpenSSH uses a trusted X11 cookie if creation of an untrusted cookie fails | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Mac OS X Security Update Fixes Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Avaya Products Red Hat Tampered OpenSSH Packages - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| About Security Update 2008-002 | af854a3a-2127-422b-91ae-364da2661108 | docs.info.apple.com | |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| ASA-2008-399 (RHSA-2008-0855) | af854a3a-2127-422b-91ae-364da2661108 | support.avaya.com | |
| USN-566-1: OpenSSH vulnerability | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| [security-announce] SUSE Security Summary Report SUSE-SR:2007:022 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| SUSE Update for Multiple Packages - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| APPLE-SA-2008-03-18 Security Update 2008-002 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| Gentoo Linux Documentation -- OpenSSH: Security bypass | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| [SECURITY] Fedora Core 6 Update: openssh-4.3p2-25.fc6 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Support / Security / Advisories / / MDKSA-2007:236 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| www.openssh.com/txt/release-4.7 | af854a3a-2127-422b-91ae-364da2661108 | www.openssh.com | |
| Debian -- Security Information -- DSA-1576-1 openssh | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp | af854a3a-2127-422b-91ae-364da2661108 | h20000.www2.hp.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Debian update for openssh - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Gentoo Bug 191321 - net-misc/openssh <4.7 X11 cookie privelege escalation (CVE-2007-4752) | af854a3a-2127-422b-91ae-364da2661108 | bugs.gentoo.org | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2008-08-28 | Mark J Cox | This issue did not affect the OpenSSH packages as distributed with Red Hat Enterprise Linux 2.1 or 3, as they do not support Trusted X11 forwarding. For Red Hat Enterprise Linux 4 and 5, this issue was addressed via: https://rhn.redhat.com/errata/RHSA-2008-0855.html |
There are currently no legacy QID mappings associated with this CVE.