Multiple CRLF injection vulnerabilities in session.c in sshd in OpenSSH before 7.2p2 allow remote authenticated users to bypass intended shell-command restrictions via crafted X11 forwarding data, related to the (1) doauthenticated1 and (2) sessionx11_req functions.
{
"unresolved_ranges": [
{
"cpe": "cpe:2.3:a:openbsd:openssh:*:p1:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "7.2"
}
]
},
{
"cpe": "cpe:2.3:o:oracle:vm_server:3.2:*:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "3.2"
}
]
}
]
}