{ "id": "CVE-2007-4752", "sourceIdentifier": "cve@mitre.org", "published": "2007-09-12T01:17:00.000", "lastModified": "2018-10-15T21:37:09.420", "vulnStatus": "Modified", "descriptions": [ { "lang": "en", "value": "ssh in OpenSSH before 4.7 does not properly handle when an untrusted cookie cannot be created and uses a trusted X11 cookie instead, which allows attackers to violate intended policy and gain privileges by causing an X client to be treated as trusted." }, { "lang": "es", "value": "ssh en OpenSSH anterior a 4.7 no maneja adecuadamente cuando una cookie no confiable no puede ser creada y utiliza una cookie X11 confiable en su lugar, lo cual permite a los atacantes violar pol\u00edticas establecidas y obtener privilegios provocando que un cliente X sea tratado como confiable." } ], "vendorComments": [ { "organization": "Red Hat", "comment": "This issue did not affect the OpenSSH packages as distributed with Red Hat Enterprise Linux 2.1 or 3, as they do not support Trusted X11 forwarding.\n\nFor Red Hat Enterprise Linux 4 and 5, this issue was addressed via: https://rhn.redhat.com/errata/RHSA-2008-0855.html\n", "lastModified": "2008-08-28T00:00:00" } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P", "accessVector": "NETWORK", "accessComplexity": "LOW", "authentication": "NONE", "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "availabilityImpact": "PARTIAL", "baseScore": 7.5 }, "baseSeverity": "HIGH", "exploitabilityScore": 10.0, "impactScore": 6.4, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": true, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-20" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:*", "versionEndIncluding": "4.6", "matchCriteriaId": "A410C8F9-717C-4657-91DD-BAEAB53ECC16" }, { "vulnerable": true, "criteria": "cpe:2.3:a:openbsd:openssh:4.0:*:*:*:*:*:*:*", "matchCriteriaId": "E003AB3C-8DF3-4AE8-82A3-984F30E5599B" }, { "vulnerable": true, "criteria": "cpe:2.3:a:openbsd:openssh:4.0p1:*:*:*:*:*:*:*", "matchCriteriaId": "5EBE75FE-DDE2-43BA-80EF-15A6698EABC9" }, { "vulnerable": true, "criteria": "cpe:2.3:a:openbsd:openssh:4.1:*:*:*:*:*:*:*", "matchCriteriaId": "1FF67D77-02AC-4807-984D-C5AE9799F051" }, { "vulnerable": true, "criteria": "cpe:2.3:a:openbsd:openssh:4.1p1:*:*:*:*:*:*:*", "matchCriteriaId": "683B26F0-5EA2-455A-8948-27C100BBA3AC" }, { "vulnerable": true, "criteria": "cpe:2.3:a:openbsd:openssh:4.2:*:*:*:*:*:*:*", "matchCriteriaId": "E5A75B23-2DD7-4EB2-BEAA-049FF4E51A14" }, { "vulnerable": true, "criteria": "cpe:2.3:a:openbsd:openssh:4.2p1:*:*:*:*:*:*:*", "matchCriteriaId": "7279E1EC-DEBC-4ACC-925D-06A7697C162F" }, { "vulnerable": true, "criteria": "cpe:2.3:a:openbsd:openssh:4.3:*:*:*:*:*:*:*", "matchCriteriaId": "7910598E-BEC1-4644-9DE4-D8BE505A4F9E" }, { "vulnerable": true, "criteria": "cpe:2.3:a:openbsd:openssh:4.3p1:*:*:*:*:*:*:*", "matchCriteriaId": "FB416D0C-6C86-450F-8917-D4B1BD82AB1E" }, { "vulnerable": true, "criteria": "cpe:2.3:a:openbsd:openssh:4.3p2:*:*:*:*:*:*:*", "matchCriteriaId": "3640CCC9-EC4A-44A4-B747-7BAAAD3460C7" }, { "vulnerable": true, "criteria": "cpe:2.3:a:openbsd:openssh:4.4:*:*:*:*:*:*:*", "matchCriteriaId": "B2DD362E-9EA9-4E88-9A94-D7B471EB1FD4" }, { "vulnerable": true, "criteria": "cpe:2.3:a:openbsd:openssh:4.4p1:*:*:*:*:*:*:*", "matchCriteriaId": "E3094069-AC2E-43BD-8094-D48E2526DECC" }, { "vulnerable": true, "criteria": "cpe:2.3:a:openbsd:openssh:4.5:*:*:*:*:*:*:*", "matchCriteriaId": "9B72CFB3-39C7-469C-AA59-69F5B8993BF7" } ] } ] } ], "references": [ { "url": "http://bugs.gentoo.org/show_bug.cgi?id=191321", "source": "cve@mitre.org" }, { "url": "http://docs.info.apple.com/article.html?artnum=307562", "source": "cve@mitre.org" }, { "url": "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01271085", "source": "cve@mitre.org" }, { "url": "http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html", "source": "cve@mitre.org" }, { "url": "http://lists.opensuse.org/opensuse-security-announce/2007-10/msg00008.html", "source": "cve@mitre.org" }, { "url": "http://security.gentoo.org/glsa/glsa-200711-02.xml", "source": "cve@mitre.org" }, { "url": "http://securityreason.com/securityalert/3126", "source": "cve@mitre.org" }, { "url": "http://support.avaya.com/elmodocs2/security/ASA-2008-399.htm", "source": "cve@mitre.org" }, { "url": "http://www.debian.org/security/2008/dsa-1576", "source": "cve@mitre.org" }, { "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2007:236", "source": "cve@mitre.org" }, { "url": "http://www.openssh.com/txt/release-4.7", "source": "cve@mitre.org" }, { "url": "http://www.redhat.com/support/errata/RHSA-2008-0855.html", "source": "cve@mitre.org" }, { "url": "http://www.securityfocus.com/archive/1/479760/100/0/threaded", "source": "cve@mitre.org" }, { "url": "http://www.securityfocus.com/archive/1/483748/100/200/threaded", "source": "cve@mitre.org" }, { "url": "http://www.securityfocus.com/bid/25628", "source": "cve@mitre.org" }, { "url": "http://www.ubuntu.com/usn/usn-566-1", "source": "cve@mitre.org" }, { "url": "http://www.vupen.com/english/advisories/2007/3156", "source": "cve@mitre.org" }, { "url": "http://www.vupen.com/english/advisories/2008/0924/references", "source": "cve@mitre.org" }, { "url": "http://www.vupen.com/english/advisories/2008/2821", "source": "cve@mitre.org" }, { "url": "https://bugzilla.redhat.com/show_bug.cgi?id=280471", "source": "cve@mitre.org" }, { "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/36637", "source": "cve@mitre.org" }, { "url": "https://issues.rpath.com/browse/RPL-1706", "source": "cve@mitre.org", "tags": [ "Patch" ] }, { "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10809", "source": "cve@mitre.org" }, { "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5599", "source": "cve@mitre.org" }, { "url": "https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00214.html", "source": "cve@mitre.org" } ] }