OpenSSH 4.4 up to versions before 4.9 allows remote authenticated users to bypass the sshd_config ForceCommand directive by modifying the .ssh/rc session file.
CVSS Details
- CVSS 3.1 Base Score: 8.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Openssh | — | Apply OS X security update 2008-006Upgrade macOS to the latest version | Dec 16, 2011 | Apr 2, 2008 |
| Debian | — | Upgrade openssh | Jul 30, 2024 | Apr 2, 2008 |
| Gentoo Linux | — | Upgrade net-misc/openssh. | Oct 30, 2017 | Apr 2, 2008 |
| Ibm Aix | — | Apply the fix or workaround for ssh_advisory | Nov 30, 2017 | Apr 2, 2008 |
| Openbsd Openssh | — | Upgrade to OpenSSH version 4.9 | Dec 5, 2012 | Apr 2, 2008 |
| Suse | — | Upgrade openssh-askpassUpgrade opensshUpgrade suse-release | Feb 17, 2015 | Apr 2, 2008 |
| Ubuntu | — | Upgrade openssh-server | Nov 8, 2024 | Apr 2, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub