Unrated severityNVD Advisory· Published Jan 25, 2008· Updated Apr 23, 2026
CVE-2007-6415
CVE-2007-6415
Description
scponly 4.6 and earlier allows remote authenticated users to bypass intended restrictions and execute arbitrary code by invoking scp, as implemented by OpenSSH, with the -F and -o options.
Affected products
2cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:*
- cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- secunia.com/advisories/28538nvdPatchVendor Advisory
- bugs.debian.org/cgi-bin/bugreport.cginvdExploit
- bugs.gentoo.org/show_bug.cginvd
- secunia.com/advisories/28944nvd
- secunia.com/advisories/28981nvd
- security.gentoo.org/glsa/glsa-200802-06.xmlnvd
- www.debian.org/security/2008/dsa-1473nvd
- www.redhat.com/archives/fedora-package-announce/2008-February/msg00546.htmlnvd
- www.redhat.com/archives/fedora-package-announce/2008-February/msg00595.htmlnvd
News mentions
0No linked articles in our index yet.