Description
OpenSSH 4.4 up to versions before 4.9 allows remote authenticated users to bypass the sshd_config ForceCommand directive by modifying the .ssh/rc session file.
CVSS vector
AV:N/AC:L/C:P/I:P/A:PExploitability: 8.0 | Impact: 6.4 Affected Packages2 packages
🔴Vulnerability Details
3GHSAGHSA-4fmw-7mgw-xgw8: OpenSSH 4↗2022-05-03 ▶ CVEListCVE-2008-1657: OpenSSH 4↗2008-04-02 ▶ OSVCVE-2008-1657: OpenSSH 4↗2008-04-02 ▶ 📋Vendor Advisories
3UbuntuOpenSSH vulnerabilities↗2008-10-01 ▶ Red Hatopenssh: commands in ~/.ssh/rc override ForceCommand directive↗2008-03-31 ▶ DebianCVE-2008-1657: openssh - OpenSSH 4.4 up to versions before 4.9 allows remote authenticated users to bypas...↗2008 ▶ 💬Community
2BugzillaCVE-2008-1657 openssh: commands in ~/.ssh/rc override ForceCommand directive↗2008-04-02 ▶ BugzillaCVE-2007-4752 CVE-2008-1657 openssh multiple issues [Fedora 7]↗2007-09-06 ▶