scponly 4.6 and earlier allows remote authenticated users to bypass intended restrictions and execute arbitrary code by invoking scp, as implemented by OpenSSH, with the -F and -o options.
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00595.html
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00546.html
http://www.debian.org/security/2008/dsa-1473
http://security.gentoo.org/glsa/glsa-200802-06.xml
http://secunia.com/advisories/28981
http://secunia.com/advisories/28944