CVE-2016-3115
Last modified
CVE-2016-3115 is a medium-severity vulnerability rated 6.4/10 on the CVSS scale. Multiple CRLF injection vulnerabilities in session.c in sshd in OpenSSH before 7.2p2 allow remote authenticated users to bypass intended shell-command restrictions via crafted X11 forwarding data, related to the (1) do_authenticated1 and (2) session_x11_req functions.. EPSS estimates a 37.02% chance of exploitation in the next 30 days.
Description
Multiple CRLF injection vulnerabilities in session.c in sshd in OpenSSH before 7.2p2 allow remote authenticated users to bypass intended shell-command restrictions via crafted X11 forwarding data, related to the (1) do_authenticated1 and (2) session_x11_req functions.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Openbsd | Openssh | <= 7.2 | P1 |
| Oracle | Vm Server | 3.2 | — |
References
- http://www.openssh.com/txt/x11fwd.advVendor Advisory
- http://www.openssh.com/txt/x11fwd.advVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-3115?
How severe is CVE-2016-3115?
How do I fix CVE-2016-3115?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-3109The backend/Login/load/ script in Shopware before 5.1.5 allo…
- CVE-2016-3110mod_cluster, as used in Red Hat JBoss Web Server 2.1, allows…
- CVE-2016-3111pulp.spec in the installation process for Pulp 2.8.3 generat…
- CVE-2016-3112client/consumer/cli.py in Pulp before 2.8.3 writes consumer …
- CVE-2016-3113Cross-site scripting (XSS) vulnerability in ovirt-engine all…6.1
- CVE-2016-3114Kallithea before 0.3.2 allows remote authenticated users to …
- CVE-2016-3116CRLF injection vulnerability in Dropbear SSH before 2016.72 …
- CVE-2016-3118CRLF injection vulnerability in CA API Gateway (formerly Lay…
- CVE-2016-3119The process_db_args function in plugins/kdb/ldap/libkdb_ldap…
- CVE-2016-3120The validate_as_request function in kdc_util.c in the Key Di…
- CVE-2016-3124The sanitycheck module in SimpleSAMLphp before 1.14.1 allows…
- CVE-2016-3125The mod_tls module in ProFTPD before 1.3.5b and 1.3.6 before…
Are you affected by CVE-2016-3115?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
