8.5
CVSSv2

CVE-2007-6415

Published: 25/01/2008 Updated: 05/09/2008
CVSS v2 Base Score: 8.5 | Impact Score: 9.2 | Exploitability Score: 8
VMScore: 756
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:N

Vulnerability Summary

scponly 4.6 and previous versions allows remote authenticated users to bypass intended restrictions and execute arbitrary code by invoking scp, as implemented by OpenSSH, with the -F and -o options.

Vulnerable Product Search on Vulmon Subscribe to Product

debian debian linux 3.1

debian debian linux 4.0

Vendor Advisories

Joachim Breitner discovered that Subversion support in scponly is inherently insecure, allowing execution of arbitrary commands Further investigation showed that rsync and Unison support suffer from similar issues This set of issues has been assigned CVE-2007-6350 In addition, it was discovered that it was possible to invoke scp with certain opt ...