.:[ packet storm ]:.
                               
global security disclosure
global security disclosure

 ///  File Name:USN-649-1.txt
Description:
Ubuntu Security Notice 649-1 - It was discovered that the ForceCommand directive could be bypassed. If a local user created a malicious ~/.ssh/rc file, they could execute arbitrary commands as their user id. This only affected Ubuntu 7.10. USN-355-1 fixed vulnerabilities in OpenSSH. It was discovered that the fixes for this issue were incomplete. A remote attacker could attempt multiple logins, filling all available connection slots, leading to a denial of service. This only affected Ubuntu 6.06 and 7.04.
Homepage:http://security.ubuntu.com/
File Size:14795
Related CVE(s):CVE-2008-1657, CVE-2008-4109
Last Modified:Oct 1 22:51:55 2008
MD5 Checksum:58000d9dd0f2929fcc69919a75c30afe

 .:. Back