CVE-2007-6415: Code Injection
Published Jan 24, 2008
·Updated
scponly 4.6 and earlier allows remote authenticated users to bypass intended restrictions and execute arbitrary code by invoking scp, as implemented by OpenSSH, with the -F and -o options.
Affected Software
2 affected components
Debian Debian Linux=3.1
Debian Debian Linux=4.0
Remediation
Patch Available
Event History
Jan 25, 2008
CVE Published
12:00 AM
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-6415?
CVE-2007-6415 has a medium severity level due to its ability to allow authenticated users to execute arbitrary code.
2
What versions of scponly are affected by CVE-2007-6415?
CVE-2007-6415 affects scponly version 4.6 and earlier.
3
How do I fix CVE-2007-6415?
To fix CVE-2007-6415, upgrade scponly to a version later than 4.6 that addresses this vulnerability.
4
What platforms are impacted by CVE-2007-6415?
CVE-2007-6415 impacts Debian Linux versions 3.1 and 4.0.
5
Can CVE-2007-6415 be exploited remotely?
Yes, CVE-2007-6415 can be exploited remotely by authenticated users.