Medium severity6.4NVD Advisory· Published Mar 22, 2016· Updated May 6, 2026
CVE-2016-3115
CVE-2016-3115
Description
Multiple CRLF injection vulnerabilities in session.c in sshd in OpenSSH before 7.2p2 allow remote authenticated users to bypass intended shell-command restrictions via crafted X11 forwarding data, related to the (1) do_authenticated1 and (2) session_x11_req functions.
Affected products
2- cpe:2.3:o:oracle:vm_server:3.2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
25- www.openssh.com/txt/x11fwd.advnvdVendor Advisory
- www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlnvdVendor Advisory
- cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/session.cnvd
- cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/session.c.diffnvd
- lists.fedoraproject.org/pipermail/package-announce/2016-April/183101.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2016-April/183122.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2016-March/178838.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2016-March/179924.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2016-March/180491.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2016-May/184264.htmlnvd
- packetstormsecurity.com/files/136234/OpenSSH-7.2p1-xauth-Command-Injection-Bypass.htmlnvd
- rhn.redhat.com/errata/RHSA-2016-0465.htmlnvd
- rhn.redhat.com/errata/RHSA-2016-0466.htmlnvd
- seclists.org/fulldisclosure/2016/Mar/46nvd
- seclists.org/fulldisclosure/2016/Mar/47nvd
- www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlnvd
- www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlnvd
- www.securityfocus.com/bid/84314nvd
- www.securitytracker.com/id/1035249nvd
- bto.bluecoat.com/security-advisory/sa121nvd
- github.com/tintinweb/pub/tree/master/pocs/cve-2016-3115nvd
- lists.debian.org/debian-lts-announce/2018/09/msg00010.htmlnvd
- security.gentoo.org/glsa/201612-18nvd
- www.exploit-db.com/exploits/39569/nvd
- www.freebsd.org/security/advisories/FreeBSD-SA-16:14.openssh.ascnvd
News mentions
0No linked articles in our index yet.