PT-2004-1701 · Rssh · Rssh
William F. Mccaw
·
Published
2004-06-30
·
Updated
2017-07-11
·
CVE-2004-0609
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
rssh versions 2.0 through 2.1.x
Description
The issue allows remote authenticated users to determine the existence of files in a directory outside the jail by expanding command line arguments before entering a chroot jail.
Recommendations
For versions 2.0 through 2.1.x, consider restricting access to sensitive directories until a patch is available. As a temporary workaround, limit the ability of remote authenticated users to execute commands that could exploit this issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rssh