[Bug 227322] [NEW] [openssh] [CVE-2008-1657] possibility to bypass global ForceCommand directive

2008-05-06 Thread hk47
*** This bug is a security vulnerability *** Public security bug reported: Quoting CVE-2008-1657: OpenSSH before 4.9 allows remote authenticated users to bypass the sshd_config ForceCommand directive by modifying the .ssh/rc session file. ** Affects: openssh (Ubuntu) Importance: Undecided

[Bug 227322] [NEW] [openssh] [CVE-2008-1657] possibility to bypass global ForceCommand directive

2008-05-06 Thread hk47
*** This bug is a security vulnerability *** Public security bug reported: Quoting CVE-2008-1657: OpenSSH before 4.9 allows remote authenticated users to bypass the sshd_config ForceCommand directive by modifying the .ssh/rc session file. ** Affects: openssh (Ubuntu) Importance: Undecided