CVE-2008-1657
OpenSSH 4.4 up to versions before 4.9 allows remote authenticated users to bypass the sshd_config ForceCommand directive by modifying the .ssh/rc session file.
- Openbsd Openssh
- = 4.4, 4.4p1, 4.5, 4.6, 4.7, 4.8
- Fix
- Available
- CVSS 2.0
- 6.5 MEDIUM
- EPSS
- 2.2% (81th percentile)
- Weakness
- CWE-264
- NVD status
- Modified
- Published
- 2008-04-02
CVE-2008-1657 at NVD
4 known exploits for CVE-2008-1657
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-Exploit-Research-Development
Exploit for Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in Openssl
Exploit for Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in Openssl
Exploit for Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in Openssl