PT-2006-2329 · Rssh · Rssh
Russ Allbery
·
Publicado
2006-03-20
·
Atualizado
2017-07-20
·
CVE-2006-1320
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
rssh version 2.3.0
Description
The issue is related to a problem in the util.c file of rssh, where the lack of braces to define a block causes a check to always succeed, allowing rsync and rdist to bypass intended access restrictions defined in rssh.conf.
Recommendations
For rssh version 2.3.0, consider modifying the util.c file to properly use braces and define blocks, ensuring that access restrictions in rssh.conf are correctly enforced. As a temporary workaround, restrict access to rsync and rdist until the issue is resolved.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Rssh