OpenSSH X Connections Session Hijacking Vulnerability
BID:28444
Info
OpenSSH X Connections Session Hijacking Vulnerability
| Bugtraq ID: | 28444 |
| Class: | Design Error |
| CVE: |
CVE-2008-1483 |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 25 2008 12:00AM |
| Updated: | Mar 19 2015 08:50AM |
| Credit: | Timo Juhani Lindfors is credited with the discovery of this vulnerability. |
| Vulnerable: |
Ubuntu Ubuntu Linux 7.10 sparc Ubuntu Ubuntu Linux 7.10 powerpc Ubuntu Ubuntu Linux 7.10 i386 Ubuntu Ubuntu Linux 7.10 amd64 Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.10 sparc Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 Turbolinux Turbolinux Server 10.0 Turbolinux Turbolinux Server 11 x64 Turbolinux Turbolinux Server 11 Turbolinux Turbolinux Server 10.0.0 x64 TurboLinux Personal TurboLinux Multimedia Turbolinux FUJI 0 Turbolinux Appliance Server Workgroup Edition 1.0 Turbolinux Appliance Server Hosting Edition 1.0 Turbolinux Appliance Server 1.0 Workgroup Edition Turbolinux Appliance Server 1.0 Hosting Edition Turbolinux Appliance Server 2.0 Tevfik Karagulle cwRsync 2.0.10 Tevfik Karagulle cwRsync 2.0.9 SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise Server 10 SuSE SUSE Linux Enterprise SDK 10.SP1 SuSE SUSE Linux Enterprise SDK 10 SP1 SuSE SUSE Linux Enterprise SDK 10 SuSE SUSE Linux Enterprise Desktop 10 SP1 SuSE SUSE Linux Enterprise Desktop 10 SuSE SUSE Linux Enterprise 10 SP1 DEBUGINFO SuSE openSUSE 10.3 SuSE Linux Professional 10.2 x86_64 SuSE Linux Personal 10.2 x86_64 Sun Solaris 9_x86 Sun Solaris 9_sparc Sun Solaris 10_x86 Slackware Linux 10.2 Slackware Linux 10.1 Slackware Linux 10.0 Slackware Linux 9.1 Slackware Linux 9.0 Slackware Linux 8.1 Slackware Linux 12.0 Slackware Linux 11.0 S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux Standard Server 8.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. SuSE Linux Open-Xchange 4.1 S.u.S.E. openSUSE 10.2 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux POS 9 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 10.2 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 10.2 S.u.S.E. Linux Personal 10.1 S.u.S.E. Linux 10.1 x86-64 S.u.S.E. Linux 10.1 x86 S.u.S.E. Linux 10.1 ppc rPath rPath Linux 1 rPath Appliance Platform Linux Service 1 OpenSSH OpenSSH 4.2 OpenSSH OpenSSH 4.1 p1 OpenSSH OpenSSH 4.1 OpenSSH OpenSSH 4.0 p1 OpenSSH OpenSSH 4.0 OpenSSH OpenSSH 3.9 p1 OpenSSH OpenSSH 3.8.1 p1 OpenSSH OpenSSH 3.8 p1 OpenSSH OpenSSH 3.7.2 p1 OpenSSH OpenSSH 3.7.1 p2 OpenSSH OpenSSH 3.7.1 p1 OpenSSH OpenSSH 3.7.1 OpenSSH OpenSSH 3.7 p1 OpenSSH OpenSSH 3.7 .1p2 OpenSSH OpenSSH 3.7 OpenSSH OpenSSH 3.6.1 p2 OpenSSH OpenSSH 3.6.1 p1 OpenSSH OpenSSH 3.6.1 OpenSSH OpenSSH 3.5 p1 OpenSSH OpenSSH 3.5 OpenSSH OpenSSH 3.4 p1-7 OpenSSH OpenSSH 3.4 p1-6 OpenSSH OpenSSH 3.4 p1-5 OpenSSH OpenSSH 3.4 p1-4 OpenSSH OpenSSH 3.4 p1-3 OpenSSH OpenSSH 3.4 p1-2 OpenSSH OpenSSH 3.4 p1-1 OpenSSH OpenSSH 3.4 p1 OpenSSH OpenSSH 3.4 OpenSSH OpenSSH 3.3 p1 OpenSSH OpenSSH 3.3 OpenSSH OpenSSH 3.2.3 p1 OpenSSH OpenSSH 3.2.2 p1 OpenSSH OpenSSH 3.2 OpenSSH OpenSSH 3.1 p1 OpenSSH OpenSSH 3.1 OpenSSH OpenSSH 3.0.2 p1 OpenSSH OpenSSH 3.0.2 OpenSSH OpenSSH 3.0.1 p1 OpenSSH OpenSSH 3.0.1 OpenSSH OpenSSH 3.0 p1 OpenSSH OpenSSH 3.0 OpenSSH OpenSSH 2.9.9 OpenSSH OpenSSH 2.9 p2 OpenSSH OpenSSH 2.9 p1 OpenSSH OpenSSH 2.9 OpenSSH OpenSSH 2.5.2 OpenSSH OpenSSH 2.5.1 OpenSSH OpenSSH 2.5 OpenSSH OpenSSH 2.3 OpenSSH OpenSSH 2.2 .0p1 OpenSSH OpenSSH 2.2 OpenSSH OpenSSH 2.1.1 OpenSSH OpenSSH 2.1 OpenSSH OpenSSH 1.2.3 OpenSSH OpenSSH 1.2.2 OpenSSH OpenSSH 4.9 OpenSSH OpenSSH 4.8 OpenSSH OpenSSH 4.7 OpenSSH OpenSSH 4.6p1 OpenSSH OpenSSH 4.6 OpenSSH OpenSSH 4.5 OpenSSH OpenSSH 4.4.p1 OpenSSH OpenSSH 4.4 OpenSSH OpenSSH 4.3p2 OpenSSH OpenSSH 4.3p1 OpenSSH OpenSSH 4.2p1 OpenBSD OpenBSD 4.3 OpenBSD OpenBSD 4.2 OpenBSD OpenBSD 4.1 NetBSD NetBSD 3.0.2 NetBSD NetBSD 3.0.1 NetBSD NetBSD Current NetBSD NetBSD 4.0 NetBSD NetBSD 3.1 Navision Financials Server 3.0 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 Mandriva Linux Mandrake 2007.0 x86_64 Mandriva Linux Mandrake 2007.0 MandrakeSoft Multi Network Firewall 2.0 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 4.0 IBM AIX 6.1 IBM AIX 5.3 IBM AIX 5.2 HP HP-UX B.11.31 HP HP-UX B.11.23 HP HP-UX B.11.11 Globus GSI-OpenSSH 4.2 Globus Globus Toolkit 4.1.3 Globus Globus Toolkit 4.1.2 Globus Globus Toolkit 4.1.1 Globus Globus Toolkit 4.1 Globus Globus Toolkit 4.0.7 Globus Globus Toolkit 4.0.4 Globus Globus Toolkit 4.0.3 Globus Globus Toolkit 4.0.2 Globus Globus Toolkit 4.0.1 Globus Globus Toolkit 4.0 Gentoo Linux FreeBSD FreeBSD 6.0 -STABLE FreeBSD FreeBSD 6.0 -RELEASE FreeBSD FreeBSD 5.5 -STABLE FreeBSD FreeBSD 5.5 -RELEASE FreeBSD FreeBSD 5.4 -RELENG FreeBSD FreeBSD 5.4 -RELEASE FreeBSD FreeBSD 5.4 -PRERELEASE FreeBSD FreeBSD 5.3 -STABLE FreeBSD FreeBSD 5.3 -RELENG FreeBSD FreeBSD 5.3 -RELEASE FreeBSD FreeBSD 5.3 FreeBSD FreeBSD 5.2.1 -RELEASE FreeBSD FreeBSD 5.2 -RELENG FreeBSD FreeBSD 5.2 -RELEASE FreeBSD FreeBSD 5.2 FreeBSD FreeBSD 5.1 -RELENG FreeBSD FreeBSD 5.1 -RELEASE FreeBSD FreeBSD 5.1 FreeBSD FreeBSD 5.0 -RELENG FreeBSD FreeBSD 5.0 FreeBSD FreeBSD 7.1 -RELEASE-p1 FreeBSD FreeBSD 7.0 -RELENG FreeBSD FreeBSD 7.0 FreeBSD FreeBSD 6.3 -RELENG FreeBSD FreeBSD 6.3 FreeBSD FreeBSD 6.2 -STABLE FreeBSD FreeBSD 6.2 -RELENG FreeBSD FreeBSD 6.2 FreeBSD FreeBSD 6.1 -STABLE FreeBSD FreeBSD 6.1 -RELEASE FreeBSD FreeBSD 5.5 FreeBSD FreeBSD 5.4-STABLE Avaya Interactive Response 3.0 Avaya Interactive Response 2.0 Attachmate Reflection for Secure IT 7.0 Apple Mac OS X Server 10.5.4 Apple Mac OS X Server 10.5.3 Apple Mac OS X Server 10.5.2 Apple Mac OS X Server 10.5.1 Apple Mac OS X Server 10.4.11 Apple Mac OS X Server 10.4.10 Apple Mac OS X Server 10.4.9 Apple Mac OS X Server 10.4.8 Apple Mac OS X Server 10.4.7 Apple Mac OS X Server 10.4.6 Apple Mac OS X Server 10.4.5 Apple Mac OS X Server 10.4.4 Apple Mac OS X Server 10.4.3 Apple Mac OS X Server 10.4.2 Apple Mac OS X Server 10.4.1 Apple Mac OS X Server 10.5 Apple Mac OS X 10.5.4 Apple Mac OS X 10.5.3 Apple Mac OS X 10.5.2 Apple Mac OS X 10.5.1 Apple Mac OS X 10.4.11 Apple Mac OS X 10.4.10 Apple Mac OS X 10.4.9 Apple Mac OS X 10.4.8 Apple Mac OS X 10.4.7 Apple Mac OS X 10.4.6 Apple Mac OS X 10.4.5 Apple Mac OS X 10.4.4 Apple Mac OS X 10.4.3 Apple Mac OS X 10.4.2 Apple Mac OS X 10.4.1 Apple Mac OS X 10.4 Apple Mac OS X 10.5 |
| Not Vulnerable: |
Tevfik Karagulle cwRsync 2.1.2 OpenSSH OpenSSH 5.0 Attachmate Reflection for Secure IT 7.0 SP1 Apple Mac OS X Server 10.5.5 Apple Mac OS X 10.5.5 |
Discussion
OpenSSH X Connections Session Hijacking Vulnerability
OpenSSH is prone to a vulnerability that allows attackers to hijack forwarded X connections.
Successfully exploiting this issue may allow an attacker run arbitrary shell commands with the privileges of the user running the affected application.
This issue affects OpenSSH 4.3p2; other versions may also be affected.
NOTE: This issue affects the portable version of OpenSSH and may not affect OpenSSH running on OpenBSD.
OpenSSH is prone to a vulnerability that allows attackers to hijack forwarded X connections.
Successfully exploiting this issue may allow an attacker run arbitrary shell commands with the privileges of the user running the affected application.
This issue affects OpenSSH 4.3p2; other versions may also be affected.
NOTE: This issue affects the portable version of OpenSSH and may not affect OpenSSH running on OpenBSD.
Exploit / POC
OpenSSH X Connections Session Hijacking Vulnerability
A specific exploit is not required. The attacker would only need to listen to port 6010 with a program such as VNC or NC.
A specific exploit is not required. The attacker would only need to listen to port 6010 with a program such as VNC or NC.
Solution / Fix
OpenSSH X Connections Session Hijacking Vulnerability
Solution:
Updates are available. Please see the references for more information.
FreeBSD FreeBSD 7.0
OpenBSD OpenBSD 4.3
FreeBSD FreeBSD 6.1 -RELEASE
Apple Mac OS X Server 10.5
FreeBSD FreeBSD 5.4-STABLE
FreeBSD FreeBSD 7.0 -RELENG
OpenBSD OpenBSD 4.1
Apple Mac OS X Server 10.5.2
Apple Mac OS X 10.5.3
Tevfik Karagulle cwRsync 2.0.9
FreeBSD FreeBSD 5.1
FreeBSD FreeBSD 5.2 -RELENG
FreeBSD FreeBSD 5.3 -STABLE
FreeBSD FreeBSD 5.4 -PRERELEASE
FreeBSD FreeBSD 6.0 -STABLE
FreeBSD FreeBSD 6.0 -RELEASE
Solution:
Updates are available. Please see the references for more information.
FreeBSD FreeBSD 7.0
-
FreeBSD openssh.patch
http://security.FreeBSD.org/patches/SA-08:05/openssh.patch
OpenBSD OpenBSD 4.3
-
OpenBSD 002_openssh2.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.3/common/002_openssh2.patc h
FreeBSD FreeBSD 6.1 -RELEASE
-
FreeBSD openssh.patch
http://security.FreeBSD.org/patches/SA-08:05/openssh.patch
Apple Mac OS X Server 10.5
-
Apple MacOSXServerUpdCombo10.5.5.dmg
http://www.apple.com/support/downloads/
FreeBSD FreeBSD 5.4-STABLE
-
FreeBSD openssh.patch
http://security.FreeBSD.org/patches/SA-08:05/openssh.patch
FreeBSD FreeBSD 7.0 -RELENG
-
FreeBSD openssh.patch
http://security.FreeBSD.org/patches/SA-08:05/openssh.patch
OpenBSD OpenBSD 4.1
-
OpenBSD 016_openssh2.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.1/common/016_openssh2.patc h
Apple Mac OS X Server 10.5.2
-
Apple MacOSXServerUpdCombo10.5.5.dmg
http://www.apple.com/support/downloads/
Apple Mac OS X 10.5.3
-
Apple MacOSXUpdCombo10.5.5.dmg
http://www.apple.com/support/downloads/
Tevfik Karagulle cwRsync 2.0.9
-
Tevfik Karagulle cwRsync_2.1.2_Installer.zip
http://downloads.sourceforge.net/sereds/cwRsync_2.1.2_Installer.zip?mo dtime=1207503998&big_mirror=0
FreeBSD FreeBSD 5.1
-
FreeBSD openssh.patch
http://security.FreeBSD.org/patches/SA-08:05/openssh.patch
FreeBSD FreeBSD 5.2 -RELENG
-
FreeBSD openssh.patch
http://security.FreeBSD.org/patches/SA-08:05/openssh.patch
FreeBSD FreeBSD 5.3 -STABLE
-
FreeBSD openssh.patch
http://security.FreeBSD.org/patches/SA-08:05/openssh.patch
FreeBSD FreeBSD 5.4 -PRERELEASE
-
FreeBSD openssh.patch
http://security.FreeBSD.org/patches/SA-08:05/openssh.patch
FreeBSD FreeBSD 6.0 -STABLE
-
FreeBSD openssh.patch
http://security.FreeBSD.org/patches/SA-08:05/openssh.patch
FreeBSD FreeBSD 6.0 -RELEASE
-
FreeBSD openssh.patch
http://security.FreeBSD.org/patches/SA-08:05/openssh.patch
References
OpenSSH X Connections Session Hijacking Vulnerability
References:
References:
- About the security content of Mac OS X v10.5.5 and Security Update 2008-006 (Apple)
- OpenBSD 4.1 Errata Page (OpenBSD)
- OpenBSD 4.2 Errata Page (OpenBSD)
- OpenBSD 4.3 Errata Page (OpenBSD)
- OpenSSH 5.0 release notes (OpenSSH)
- OpenSSH Homepage (OpenSSH)
- Release Name: 2.1.2 (Tevfik Karagulle)
- ssh: unprivileged users may hijack forwarded X connections by listening on port (Timo Juhani Lindfors)
- HPSBUX02337 SSRT080072 rev.1 - HP-UX Running HP-UX Secure Shell, Local Unauthori ([email protected])
- AIX OpenSSH multiple vulnerabilities (IBM)
- ASA-2008-205 (Avaya)
- Globus Security Advisory 2008-01: GSI-OpenSSH vulnerability (Globus)
- Security Updates in 7.0 SP1 (Attachmate)
- Sun Alert ID: 237444 (Sun Microsystems)