CVE-2007-6350

Publication date 14 December 2007

Last updated 24 July 2024


Ubuntu priority

Description

scponly 4.6 and earlier allows remote authenticated users to bypass intended restrictions and execute code by invoking dangerous subcommands including (1) unison, (2) rsync, (3) svn, and (4) svnserve, as originally demonstrated by creating a Subversion (SVN) repository with malicious hooks, then using svn to trigger execution of those hooks.

Status

Package Ubuntu Release Status
scponly 9.04 jaunty
Fixed 4.6-1.1
8.10 intrepid
Fixed 4.6-1.1
8.04 LTS hardy
Fixed 4.6-1.1
7.10 gutsy
Fixed 4.6-1.1
7.04 feisty Ignored end of life, was needed
6.10 edgy Ignored end of life, was needed
6.06 LTS dapper
Fixed 4.6-1etch1build0.6.06.1

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
scponly

Access our resources on patching vulnerabilities