CVE-2014-2532: OpenBSD OpenSSH
Medium severity, CVSS 4.2. EPSS: 4.8% chance of exploitation in the next 30 days.
sshd in OpenSSH before 6.6 does not properly support wildcards on AcceptEnv lines in sshd_config, which allows remote attackers to bypass intended environment restrictions by using a substring located before a wildcard character.
Affected products
- OpenBSD OpenSSH: up to and including 6.5; version 6.0 only; version 6.1 only; version 6.2 only; version 6.3 only; version 6.4 only
- Oracle Communications User Data Repository: version 10.0.1 only
Published 2014-03-18. Last modified 2026-06-17.