CVE-2008-1657

Publication date 2 April 2008

Last updated 24 July 2024


Ubuntu priority

OpenSSH 4.4 up to versions before 4.9 allows remote authenticated users to bypass the sshd_config ForceCommand directive by modifying the .ssh/rc session file.

Status

Package Ubuntu Release Status
openssh 8.04 LTS hardy
Fixed 1:4.7p1-8ubuntu1
7.10 gutsy
Fixed 1:4.6p1-5ubuntu0.6
7.04 feisty
Not affected
6.10 edgy
Not affected
6.06 LTS dapper
Not affected

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
openssh

References

Related Ubuntu Security Notices (USN)

    • USN-649-1
    • OpenSSH vulnerabilities
    • 1 October 2008

Other references