Multiple CRLF injection vulnerabilities in session.c in OpenSSH before 7.2p2
1–3 of 3 posts
Re: Multiple CRLF injection vulnerabilities in session.c in OpenSSH before 7.2p2
#2Not a huge deal since X11Forwarding is usually disabled by default.
It is another reason for best practices of just-enough infrastructure -> smaller attack surface: disable unused features and ship server daemons with sane defaults with minimal features enabled.
Re: Multiple CRLF injection vulnerabilities in session.c in OpenSSH before 7.2p2
#3Not a huge deal since X11Forwarding is usually disabled by default. It is another reason for best practices of just-enough infrastructure -> smaller attack surface: disable unused features and ship server daemons with sane defaults with minimal features enabled.
> Not a huge deal since X11Forwarding is usually disabled by default.
Except on Red Hat… https://threatpost.com/openssh-implementations-with-x11forwa...