OpenSSH 4.4 up to versions before 4.9 allows remote authenticated users to bypass the sshd_config ForceCommand directive by modifying the .ssh/rc session file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openssh | Openbsd | 4.4 (including) | 4.4 (including) |
Openssh | Openbsd | 4.4p1 (including) | 4.4p1 (including) |
Openssh | Openbsd | 4.5 (including) | 4.5 (including) |
Openssh | Openbsd | 4.6 (including) | 4.6 (including) |
Openssh | Openbsd | 4.7 (including) | 4.7 (including) |
Openssh | Openbsd | 4.8 (including) | 4.8 (including) |
Openssh | Ubuntu | devel | * |
Openssh | Ubuntu | gutsy | * |
Openssh | Ubuntu | hardy | * |
Openssh | Ubuntu | upstream | * |