Title : OpenSSH "ForceCommand" Directive Security Bypass Weakness VUPEN ID : VUPEN/ADV-2008-1035 CVE ID : CVE-2008-1657
Rated as : Low Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2008-03-31
Technical Description
A weakness has been identified in OpenSSH, which could be exploited by local attackers to bypass security restrictions. This issue is caused by an error in the "ForceCommand" directive enabled via "sshd_config", which could be exploited by malicious users with write access to the "~/.ssh/rc" file to execute arbitrary commands.