Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2008-1657

OpenSSH 4.4 up to versions before 4.9 allows remote authenticated users to bypass the sshd_config ForceCommand directive by modifying the .ssh/rc session file.

  • Published: Apr 2, 2008
  • Updated: Apr 13, 2023
  • CVE: CVE-2008-1657
  • Severity: Medium
  • Exploit:

CVSS v2:

  • Severity: Medium
  • Score: 6.5
  • AV:N/AC:L/Au:S/C:P/I:P/A:P

CWEs:

Software From Fixed in
openbsd / openssh 4.8 4.8.x
openbsd / openssh 4.7 4.7.x
openbsd / openssh 4.4 4.4.x
openbsd / openssh 4.5 4.5.x
openbsd / openssh 4.4p1 4.4p1.x
openbsd / openssh 4.6 4.6.x