PT-2005-1100 · Scponly · Scponly

Pekka Pessi

·

Publicado

2005-12-28

·

Atualizado

2017-10-12

·

CVE-2005-4533

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions scponly versions 4.1 and earlier
Description The issue allows local users to execute arbitrary applications via "getopt" style argument specifications, which are not filtered, when both scp and rsync compatibility are enabled. Multiple vulnerabilities in the scponly package can lead to disruption of confidentiality, integrity, and availability of protected information, and can be exploited remotely.
Recommendations For scponly versions 4.1 and earlier, update to version 4.2 or later to resolve the issue. As a temporary workaround, consider disabling the scp and rsync compatibility features until a patch is available. Restrict access to the getopt style argument specifications to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-09494
CVE-2005-4533
DSA-969-1

Produtos afetados

Scponly