First published: Tue Mar 18 2014(Updated: )
sshd in OpenSSH before 6.6 does not properly support wildcards on AcceptEnv lines in sshd_config, which allows remote attackers to bypass intended environment restrictions by using a substring located before a wildcard character.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Communications User Data Repository | =10.0.1 | |
Openbsd Openssh | <=6.5 | |
Openbsd Openssh | =6.0 | |
Openbsd Openssh | =6.1 | |
Openbsd Openssh | =6.2 | |
Openbsd Openssh | =6.3 | |
Openbsd Openssh | =6.4 | |
debian/openssh | 1:8.4p1-5+deb11u3 1:9.2p1-2+deb12u2 1:9.2p1-2+deb12u3 1:9.8p1-2 1:9.8p1-3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.