Gentoo Linux Security Advisory GLSA 200802-06 – Florian Weimer from Debian discovered that scponly does not filter the – -o and -F options to the scp executable (CVE-2007-6415). Joachim Breitner reported that Subversion and rsync support invokes subcommands in an insecure manner (CVE-2007-6350). Versions less than 4.8 are affected.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/63554/glsa-200802-06.txt
Source: https://packetstormsecurity.com/files/63554/Gentoo-Linux-Security-Advisory-200802-6.html