OpenSSH 4.4 up to versions before 4.9 allows remote authenticated users to bypass the sshd_config ForceCommand directive by modifying the .ssh/rc session file.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Openssh | Openbsd | 4.4 (including) | 4.4 (including) |
| Openssh | Openbsd | 4.4p1 (including) | 4.4p1 (including) |
| Openssh | Openbsd | 4.5 (including) | 4.5 (including) |
| Openssh | Openbsd | 4.6 (including) | 4.6 (including) |
| Openssh | Openbsd | 4.7 (including) | 4.7 (including) |
| Openssh | Openbsd | 4.8 (including) | 4.8 (including) |
| Openssh | Ubuntu | devel | * |
| Openssh | Ubuntu | gutsy | * |
| Openssh | Ubuntu | hardy | * |
| Openssh | Ubuntu | upstream | * |