First published: Wed Apr 02 2008(Updated: )
OpenSSH 4.4 up to versions before 4.9 allows remote authenticated users to bypass the sshd_config ForceCommand directive by modifying the .ssh/rc session file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Openbsd Openssh | =4.8 | |
Openbsd Openssh | =4.7 | |
Openbsd Openssh | =4.4 | |
Openbsd Openssh | =4.5 | |
Openbsd Openssh | =4.4p1 | |
Openbsd Openssh | =4.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.