CVE-2014-2532: OpenBSD OpenSSH

Medium severity, CVSS 4.2. EPSS: 4.8% chance of exploitation in the next 30 days.

sshd in OpenSSH before 6.6 does not properly support wildcards on AcceptEnv lines in sshd_config, which allows remote attackers to bypass intended environment restrictions by using a substring located before a wildcard character.

Affected products

  • OpenBSD OpenSSH: up to and including 6.5; version 6.0 only; version 6.1 only; version 6.2 only; version 6.3 only; version 6.4 only
  • Oracle Communications User Data Repository: version 10.0.1 only

Published 2014-03-18. Last modified 2026-06-17.