CVE-2008-1657: Medium severity openssh vulnerability
Published Apr 2, 2008
·Updated
OpenSSH 4.4 up to versions before 4.9 allows remote authenticated users to bypass the sshdconfig ForceCommand directive by modifying the .ssh/rc session file.
Affected Software
6 affected components
OpenBSD OpenSSH=4.8
OpenBSD OpenSSH=4.7
OpenBSD OpenSSH=4.4
OpenBSD OpenSSH=4.5
OpenBSD OpenSSH=4.4p1
OpenBSD OpenSSH=4.6
Remediation
Patch Available
Patch Available
Event History
Apr 2, 2008
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-1657?
CVE-2008-1657 has a moderate severity level as it allows a remote authenticated user to bypass security configurations.
2
How do I fix CVE-2008-1657?
To fix CVE-2008-1657, upgrade OpenSSH to version 4.9 or later to ensure the bypass is eliminated.
3
Which versions of OpenSSH are affected by CVE-2008-1657?
CVE-2008-1657 affects OpenSSH versions 4.4 to 4.8, including 4.5, 4.6, 4.7, and 4.8.
4
What does the ForceCommand directive do in OpenSSH relating to CVE-2008-1657?
The ForceCommand directive is intended to restrict the commands a user can run, but it can be bypassed due to this vulnerability.
5
Who can exploit CVE-2008-1657?
CVE-2008-1657 can be exploited by remote authenticated users with access to the affected OpenSSH versions.