OpenSSH xauth Command Injection Vulnerability Exploit

An authenticated user may inject arbitrary xauth commands by sending an x11 channel request that includes a newline character in the x11 cookie. The newline acts as a command separator to the xauth binary. The injected xauth commands are performed with the effective permissions of the logged in user. This attack requires the server to have 'X11Forwarding yes' enabled. This module injects source xauth command to retrieve arbitrary files.
Platform: 
Vulnerabilty ID: 
CVE-2016-3115
Product Version: 
2016_R1
Released Date: 
Thursday, April 28, 2016 - 00:00