LWN.net Logo

gnome-ssh-askpass, openssh: privilege escalation

Package(s):gnome-ssh-askpass CVE #(s):CVE-2008-1657
Created:April 7, 2008 Updated:October 2, 2008
Description:

From the Gentoo advisory:

OpenSSH will execute the contents of the ".ssh/rc" file even when the "ForceCommand" directive is enabled in the global sshd_config (CVE-2008-1657).

Alerts:
Ubuntu USN-649-1 2008-10-01
Mandriva MDVSA-2008:098 2007-05-06
SuSE SUSE-SR:2008:009 2008-04-11
Gentoo 200804-03 2008-04-05
rPath rPSA-2008-0139-1 2008-04-04

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds