Missing sanitisation of untrusted input allows an authenticated user who is able to request X11 forwarding to inject commands to xauth(1). Injection of xauth commands grants the ability to read arbitrary files under the authenticated user's privilege. Other xauth commands allow limited information leakage, file overwrite, port probing and generally expose xauth(1), which was not written with a hostile user in mind, as an attack surface. xauth(1) is run under the user's privilege, so this vulnerability offers no additional access to unrestricted accounts, but could circumvent key or account restrictions such as sshd_config ForceCommand, authorized_keys command="..." or restricted shells. External references: http://www.openssh.com/txt/x11fwd.adv CVE assignment: http://seclists.org/oss-sec/2016/q1/593
Created openssh tracking bugs for this issue: Affects: fedora-all [bug 1316830]
openssh-7.2p2-1.fc23 has been pushed to the Fedora 23 stable repository. If problems still persist, please make note of it in this bug report.
Statement: (none)
Mitigation: Set X11Forwarding=no in sshd_config. For authorized_keys that specify a "command" restriction, this issue can be mitigated by also setting the "no-X11-forwarding" restriction. In OpenSSH 7.2 and later, the "restrict" restriction can be used instead, which includes the "no-X11-forwarding" restriction.
Upstream commit: OpenBSD CVS: http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/session.c?f=h#rev1.282 Portable OpenSSH git: https://anongit.mindrot.org/openssh.git/commit/?id=4b4bfb01cd40b9ddb948e6026ddd287cc303d871
Created gsi-openssh tracking bugs for this issue: Affects: fedora-all [bug 1318201] Affects: epel-all [bug 1318202]
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Via RHSA-2016:0466 https://rhn.redhat.com/errata/RHSA-2016-0466.html
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2016:0465 https://rhn.redhat.com/errata/RHSA-2016-0465.html
openssh-7.2p2-1.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make note of it in this bug report.
openssh-6.9p1-11.fc22 has been pushed to the Fedora 22 stable repository. If problems still persist, please make note of it in this bug report.