CVE-2008-1483
OpenSSH 4.3p2, and probably other versions, allows local users to hijack forwarded X connections by causing ssh to set DISPLAY to :10, even when another process is listening on the associated port, as demonstrated by opening TCP port 6010 (IPv4) and sniffing a cookie sent by Emacs.
- Openbsd Openssh
- = 4.3p2
- Fix
- Available
- CVSS 2.0
- 6.9 MEDIUM
- EPSS
- 0.3% (27th percentile)
- Weakness
- CWE-264
- NVD status
- Modified
- Published
- 2008-03-24
CVE-2008-1483 at NVD
1 known exploit for CVE-2008-1483
Proof-of-concept code and exploit modules indexed by Sploitus