PT-2002-2437 · Openssh · Ssh

Published

2002-12-31

·

Updated

2017-07-11

·

CVE-2002-1715

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SSH versions 1 through 3
Description The issue allows local users to bypass restricted shells, such as rbash or rksh, by uploading a script to a world-writeable directory and then executing that script to gain normal shell access.
Recommendations For SSH versions 1 through 3, restrict write access to directories to prevent uploading of malicious scripts, and consider implementing additional access controls to prevent bypassing of restricted shells.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1715

Affected Products

Ssh