PT-2006-2329 · Rssh · Rssh

Russ Allbery

·

Publicado

2006-03-20

·

Atualizado

2017-07-20

·

CVE-2006-1320

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions rssh version 2.3.0
Description The issue is related to a problem in the util.c file of rssh, where the lack of braces to define a block causes a check to always succeed, allowing rsync and rdist to bypass intended access restrictions defined in rssh.conf.
Recommendations For rssh version 2.3.0, consider modifying the util.c file to properly use braces and define blocks, ensuring that access restrictions in rssh.conf are correctly enforced. As a temporary workaround, restrict access to rsync and rdist until the issue is resolved.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-1320
DSA-1109

Produtos afetados

Rssh