PT-2019-1491 · None+1 · Rssh+1

Nick Cleaton

·

Publicado

2019-02-02

·

Atualizado

2021-07-21

·

CVE-2019-3463

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions rssh versions (affected versions not specified)
Description The issue is related to insufficient sanitization of arguments passed to rsync, which can bypass restrictions imposed by rssh, a restricted shell. This allows an attacker to execute arbitrary shell commands.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Argument Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-00902
CVE-2019-3463
DLA-1660-1
DLA-1660-2
DSA-4382-1
USN-3946-1

Produtos afetados

Ubuntu
Rssh