| /// File Name: | USN-649-1.txt | Description:
| Ubuntu Security Notice 649-1 - It was discovered that the ForceCommand directive could be bypassed. If a local user created a malicious ~/.ssh/rc file, they could execute arbitrary commands as their user id. This only affected Ubuntu 7.10. USN-355-1 fixed vulnerabilities in OpenSSH. It was discovered that the fixes for this issue were incomplete. A remote attacker could attempt multiple logins, filling all available connection slots, leading to a denial of service. This only affected Ubuntu 6.06 and 7.04. | | Homepage: | http://security.ubuntu.com/ | | File Size: | 14795 | | Related CVE(s): | CVE-2008-1657, CVE-2008-4109 | | Last Modified: | Oct 1 22:51:55 2008 | | MD5 Checksum: | 58000d9dd0f2929fcc69919a75c30afe |
|