CVE-2008-3259 (OpenSSH) [Sitemap] - HeapOverflow Computer Security Community & Forums : Heap Overflow.com

PDA

View Full Version : CVE-2008-3259 (OpenSSH)


Heap
23-07-08, 21:54
OpenSSH before 5.1 sets the SO_REUSEADDR socket option when the X11UseLocalhost configuration setting is disabled, which allows local users on some platforms to hijack the X11 forwarding port via a bind to a single IP address, as demonstrated on the HP-UX platform.

More... (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3259)