CVE Vulnerabilities

CVE-2008-1657

Published: Apr 02, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

OpenSSH 4.4 up to versions before 4.9 allows remote authenticated users to bypass the sshd_config ForceCommand directive by modifying the .ssh/rc session file.

Affected Software

NameVendorStart VersionEnd Version
OpensshOpenbsd4.4 (including)4.4 (including)
OpensshOpenbsd4.4p1 (including)4.4p1 (including)
OpensshOpenbsd4.5 (including)4.5 (including)
OpensshOpenbsd4.6 (including)4.6 (including)
OpensshOpenbsd4.7 (including)4.7 (including)
OpensshOpenbsd4.8 (including)4.8 (including)
OpensshUbuntudevel*
OpensshUbuntugutsy*
OpensshUbuntuhardy*
OpensshUbuntuupstream*

References