PT-2019-1685 · None+1 · Rssh+1

Publicado

2019-01-30

·

Atualizado

2025-03-19

·

CVE-2019-1000018

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions rssh version 2.3.4
Description The issue is related to a command injection vulnerability in the allowscp permission, which can result in local command execution. This can be exploited by an authorized SSH user with the allowscp permission. The vulnerability is due to the lack of input data sanitization, allowing an attacker to execute arbitrary shell commands.
Recommendations For version 2.3.4, consider restricting the use of the allowscp permission until a patch is available. As a temporary workaround, limit the access of authorized SSH users to minimize the risk of exploitation.

Exploit

Correção

Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-01279
CVE-2019-1000018
DLA-1650-1
DSA-4377-1
DSA-4377-2
DSA-4377-3
USN-3946-1

Produtos afetados

Ubuntu
Rssh