Live data from Hacker News

Multiple CRLF injection vulnerabilities in session.c in OpenSSH before 7.2p2

web.nvd.nist.gov

1–3 of 3 posts

Re: Multiple CRLF injection vulnerabilities in session.c in OpenSSH before 7.2p2

#2
Not a huge deal since X11Forwarding is usually disabled by default.

It is another reason for best practices of just-enough infrastructure -> smaller attack surface: disable unused features and ship server daemons with sane defaults with minimal features enabled.

Re: Multiple CRLF injection vulnerabilities in session.c in OpenSSH before 7.2p2

#3

Not a huge deal since X11Forwarding is usually disabled by default. It is another reason for best practices of just-enough infrastructure -> smaller attack surface: disable unused features and ship server daemons with sane defaults with minimal features enabled.

> Not a huge deal since X11Forwarding is usually disabled by default.

Except on Red Hat… https://threatpost.com/openssh-implementations-with-x11forwa...