scponly 4.6 and earlier allows remote authenticated users to bypass intended restrictions and execute arbitrary code by invoking scp, as implemented by OpenSSH, with the -F and -o options.
Software | From | Fixed in |
---|---|---|
debian / debian_linux | 3.1 | 3.1.x |
debian / debian_linux | 4.0 | 4.0.x |