CVE-2014-2532

sshd in OpenSSH before 6.6 does not properly support wildcards on AcceptEnv lines in sshd_config, which allows remote attackers to bypass intended environment restrictions by using a substring located before a wildcard character.

medium 4.2 CVSS 3.1
Published: Mar 18, 2014
Modified: May 28, 2026
Vendor: Oracle
Product: Communications User Data Repository
Versions: 10.0.1,6.0,6.1,6.2,6.3,6.4

Description

sshd in OpenSSH before 6.6 does not properly support wildcards on AcceptEnv lines in sshd_config, which allows remote attackers to bypass intended environment restrictions by using a substring located before a wildcard character.

References

Related CVEs