OpenSSH Client X11 Forwarding Cookie...

- AV AC AU C I A
发布: 2001-06-04
修订: 2025-04-13

OpenSSH is the free implementation of the SSH client and server protocol. It is maintained by the OpenBSD project, and distributed freely as open source software. A problem with OpenSSH makes it possible to delete arbitrary files. By connecting to a system over ssh and using X11 forwarding, a file is created in the /tmp directory as a result of the X11 forwarding. By linking the directory contained in /tmp to another directory containing the file "cookie", the cookie file will be removed by sshd upon termination of the session. This makes it possible for a local user to arbitrary delete a cookie file belonging to another user.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息