Ubuntu Security Notice 566-1 - Jan Pechanec discovered that ssh would forward trusted X11 cookies when untrusted cookie generation failed. This could lead to unintended privileges being forwarded to a remote host.
723ac7ad630c442447baba415ce306f18a8eedcd2fef5ba9b32127a0d187d85c
Mandriva Linux Security Advisory - A flaw in OpenSSH prior to 4.7 prevented ssh from properly handling when an untrusted cookie could not be created and used a trusted X11 cookie instead, which could allow attackers to violate intended policy and gain privileges by causing an X client to be treated as trusted.
b9a5ce7c195cf23dc93bea4b0e8421b2c3846ed1d22327a5e165ead7aa461f41
HP Security Bulletin - A potential security vulnerability has been identified with HP-UX running HP Secure Shell. The vulnerability could be exploited remotely to gain extended privileges.
81d835ad497f2eb1a68ba60bc8d9e611155607b707a8ea4a82d3cada3909e855
Gentoo Linux Security Advisory GLSA 200711-02 - Jan Pechanec discovered that OpenSSH uses a trusted X11 cookie when it cannot create an untrusted one. Versions less than 4.7 are affected.
ad1be1c610f7f1d9f29d591294e87e83ff9ac8007825b12f71a3bd6609587052