The default configuration of the server in MobaXterm before 8.3 has a disabled Access Control setting and consequently does not require authentication for X11 connections, which allows remote attackers to execute arbitrary commands or obtain sensitive information via X11 packets.
References
Link | Resource |
---|---|
http://blog.mobatek.net/post/mobaxterm-new-release-8.3/ | Patch Vendor Advisory |
http://www.kb.cert.org/vuls/id/316888 | Third Party Advisory US Government Resource |
http://www.securifera.com/advisories/cve-2015-7244 |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: certcc
Published: 2015-11-04T02:00:00
Updated: 2015-11-04T02:57:01
Reserved: 2015-09-18T00:00:00
Link: CVE-2015-7244
JSON object: View
NVD Information
Status : Analyzed
Published: 2015-11-04T03:59:12.950
Modified: 2015-11-04T19:32:09.857
Link: CVE-2015-7244
JSON object: View
Redhat Information
No data.
CWE