Description
Multiple CRLF injection vulnerabilities in session.c in sshd in OpenSSH before 7.2p2 allow remote authenticated users to bypass intended shell-command restrictions via crafted X11 forwarding data, related to the (1) do_authenticated1 and (2) session_x11_req functions.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1500-1 | openssh security update |
Ubuntu USN |
USN-2966-1 | OpenSSH vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T23:47:57.380Z
Reserved: 2016-03-10T00:00:00.000Z
Link: CVE-2016-3115
No data.
Status : Modified
Published: 2016-03-22T10:59:02.917
Modified: 2026-05-06T22:30:45.220
Link: CVE-2016-3115
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Ubuntu USN