Back

MEDIUM

openssh: AcceptEnv environment restriction bypass flaw

Published Mar 18, 2014

Description

sshd in OpenSSH before 6.6 does not properly support wildcards on AcceptEnv lines in sshd_config, which allows remote attackers to bypass intended environment restrictions by using a substring located before a wildcard character.

Affected products

Remediation

Red Hat statement

This issue affects the version of openssh as shipped with Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this issue as having Low security impact. This issue is not planned to be fixed in Red Hat Enterprise Linux 5 as it is now in Production 3 Phase of the support and maintenance life cycle, https://access.redhat.com/support/policy/updates/errata/

Metrics

References (27)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 18, 2014
Updated May 28, 2026
Reserved Mar 17, 2014
CISA Vulnrichment
Updated May 28, 2026
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Mar 15, 2014