PT-2019-1910 · Rsync+1 · Rsync+1

Nick Cleaton

·

Publicado

2019-02-02

·

Atualizado

2021-07-21

·

CVE-2019-3464

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions rsync (affected versions not specified)
Description The issue is related to insufficient sanitization of environment variables passed to rsync, which can bypass restrictions imposed by rssh, a restricted shell. This allows for the execution of arbitrary shell commands. The vulnerability is associated with errors in input validation. Exploitation can enable a remote attacker to execute arbitrary commands.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Initialization

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-01578
CVE-2019-3464
DLA-1660-1
DLA-1660-2
DSA-4382-1
USN-3946-1

Produtos afetados

Ubuntu
Rsync