CVE-2008-1657 (Medium ) : OpenSSH before 4.9 allows remote authenticated users to bypass the sshd_config ForceCommand directive by modifying the .ssh/rc session file.
@ -1,4 +1,3 @@
[COPY] --- SDE-COPYRIGHT-NOTE-BEGIN ---
[COPY] This copyright note is auto-generated by ./scripts/Create-CopyPatch.
[COPY]
@ -39,8 +38,7 @@
[L] OpenSource
[S] Stable
[V] 4.7p1
[V] 5.0p1
[P] X -----5---9 191.100
[D] 2766790270 openssh-4.7p1.tar.gz ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/
[D] 63382572 openssh-5.0p1.tar.gz ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/