OpenSSH does not properly drop privileges when the UseLogin option is enabled, which allows local users to execute arbitrary commands by providing the command to the ssh daemon.Referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/4646http://www.openbsd.org/errata.html#useloginhttp://www.osvdb.org/341http://archives.neohapsis.com/archives/bugtraq/2000-06/0065.htmlhttp://www.securityfocus.com/bid/1334