CVE-2014-2532
sshd in OpenSSH before 6.6 does not properly support wildcards on AcceptEnv lines in sshd_config, which allows remote attackers to bypass intended environment restrictions by using a substring located before a wildcard character.
- Oracle Communications User Data Repository
- = 10.0.1
- Fix
- Available
- CVSS 2.0
- 5.8 MEDIUM
- CVSS 3.1
- 4.2 MEDIUM
- EPSS
- 4.8% (91th percentile)
- Weakness
- CWE-20, CWE-266, CWE-264
- NVD status
- Modified
- Published
- 2014-03-18
CVE-2014-2532 at NVD
2 known exploits for CVE-2014-2532
Proof-of-concept code and exploit modules indexed by Sploitus