First published: Thu Jan 24 2008(Updated: )
scponly 4.6 and earlier allows remote authenticated users to bypass intended restrictions and execute arbitrary code by invoking scp, as implemented by OpenSSH, with the -F and -o options.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Debian Linux | =3.1 | |
Debian Linux | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-6415 has a medium severity level due to its ability to allow authenticated users to execute arbitrary code.
CVE-2007-6415 affects scponly version 4.6 and earlier.
To fix CVE-2007-6415, upgrade scponly to a version later than 4.6 that addresses this vulnerability.
CVE-2007-6415 impacts Debian Linux versions 3.1 and 4.0.
Yes, CVE-2007-6415 can be exploited remotely by authenticated users.