Back to search
CVE-2008-1657
Published: Apr 2, 2008
Modified: Aug 7, 2024
PUBLISHED
Description
OpenSSH 4.4 up to versions before 4.9 allows remote authenticated users to bypass the sshd_config ForceCommand directive by modifying the .ssh/rc session file.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
28531
vdb-entry
x_refsource_BID
http://support.attachmate.com/techdocs/2374.html
x_refsource_CONFIRM
USN-649-1
vendor-advisory
x_refsource_UBUNTU
32110
third-party-advisory
x_refsource_SECUNIA
https://issues.rpath.com/browse/RPL-2419
x_refsource_CONFIRM
APPLE-SA-2008-09-15
vendor-advisory
x_refsource_APPLE
29609
third-party-advisory
x_refsource_SECUNIA
31531
third-party-advisory
x_refsource_SECUNIA
[4.3] 001: SECURITY FIX: March 30, 2008
vendor-advisory
x_refsource_OPENBSD
http://aix.software.ibm.com/aix/efixes/security/ssh_advisory.asc
x_refsource_CONFIRM
TA08-260A
third-party-advisory
x_refsource_CERT
http://www.openssh.com/txt/release-4.9
x_refsource_CONFIRM
1019733
vdb-entry
x_refsource_SECTRACK
ADV-2008-1624
vdb-entry
x_refsource_VUPEN
ADV-2008-2584
vdb-entry
x_refsource_VUPEN
29735
third-party-advisory
x_refsource_SECUNIA
29683
third-party-advisory
x_refsource_SECUNIA
30361
third-party-advisory
x_refsource_SECUNIA
31882
third-party-advisory
x_refsource_SECUNIA
SUSE-SR:2008:009
vendor-advisory
x_refsource_SUSE
32080
third-party-advisory
x_refsource_SECUNIA
ADV-2008-2396
vdb-entry
x_refsource_VUPEN
29939
third-party-advisory
x_refsource_SECUNIA
ADV-2008-1035
vdb-entry
x_refsource_VUPEN
29602
third-party-advisory
x_refsource_SECUNIA
20080404 rPSA-2008-0139-1 gnome-ssh-askpass openssh openssh-client openssh-server
mailing-list
x_refsource_BUGTRAQ
http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0139
x_refsource_CONFIRM
29693
third-party-advisory
x_refsource_SECUNIA
MDVSA-2008:098
vendor-advisory
x_refsource_MANDRIVA
GLSA-200804-03
vendor-advisory
x_refsource_GENTOO
openssh-forcecommand-command-execution(41549)
vdb-entry
x_refsource_XF
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now