Vulnerability Description
OpenSSH 4.4 up to versions before 4.9 allows remote authenticated users to bypass the sshd_config ForceCommand directive by modifying the .ssh/rc session file.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openbsd | Openssh | 4.4 |
Related Weaknesses (CWE)
References
- ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2008-005.txt.asc
- http://aix.software.ibm.com/aix/efixes/security/ssh_advisory.asc
- http://lists.apple.com/archives/security-announce//2008/Sep/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00007.html
- http://secunia.com/advisories/29602Vendor Advisory
- http://secunia.com/advisories/29609Vendor Advisory
- http://secunia.com/advisories/29683Vendor Advisory
- http://secunia.com/advisories/29693Vendor Advisory
- http://secunia.com/advisories/29735Vendor Advisory
- http://secunia.com/advisories/29939Vendor Advisory
- http://secunia.com/advisories/30361Vendor Advisory
- http://secunia.com/advisories/31531Vendor Advisory
- http://secunia.com/advisories/31882Vendor Advisory
- http://secunia.com/advisories/32080Vendor Advisory
- http://secunia.com/advisories/32110Vendor Advisory
FAQ
What is CVE-2008-1657?
CVE-2008-1657 is a vulnerability with a CVSS score of 6.5 (MEDIUM). OpenSSH 4.4 up to versions before 4.9 allows remote authenticated users to bypass the sshd_config ForceCommand directive by modifying the .ssh/rc session file.
How severe is CVE-2008-1657?
CVE-2008-1657 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-1657?
Check the references section above for vendor advisories and patch information. Affected products include: Openbsd Openssh.