CVE-2007-6415

scponly 4.6 and earlier allows remote authenticated users to bypass intended restrictions and execute arbitrary code by invoking scp, as implemented by OpenSSH, with the -F and -o options.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*

History

21 Nov 2024, 00:40

Type Values Removed Values Added
References () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=437148 - Exploit () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=437148 - Exploit
References () http://bugs.gentoo.org/show_bug.cgi?id=203099 - () http://bugs.gentoo.org/show_bug.cgi?id=203099 -
References () http://secunia.com/advisories/28538 - Patch, Vendor Advisory () http://secunia.com/advisories/28538 - Patch, Vendor Advisory
References () http://secunia.com/advisories/28944 - () http://secunia.com/advisories/28944 -
References () http://secunia.com/advisories/28981 - () http://secunia.com/advisories/28981 -
References () http://security.gentoo.org/glsa/glsa-200802-06.xml - () http://security.gentoo.org/glsa/glsa-200802-06.xml -
References () http://www.debian.org/security/2008/dsa-1473 - () http://www.debian.org/security/2008/dsa-1473 -
References () https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00546.html - () https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00546.html -
References () https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00595.html - () https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00595.html -

Information

Published : 2008-01-25 00:00

Updated : 2025-04-09 00:30


NVD link : CVE-2007-6415

Mitre link : CVE-2007-6415

CVE.ORG link : CVE-2007-6415


JSON object : View

Products Affected

debian

  • debian_linux
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')