Secunia Logo
 
CVE Reference: CVE-2008-3259
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2008-3259

Description:
OpenSSH before 5.1 sets the SO_REUSEADDR socket option when the X11UseLocalhost configuration setting is disabled, which allows local users on some platforms to hijack the X11 forwarding port via a bind to a single IP address, as demonstrated on the HP-UX platform.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/43940

ST
  1020537

SAID
  Secunia Advisory: SA31179

CONFIRM
  http://openssh.com/security.html
  http://www.openssh.com/txt/release-5.1

BID
  30339


Return to the previous page.