PT-2004-1701 · Rssh · Rssh

William F. Mccaw

·

Published

2004-06-30

·

Updated

2017-07-11

·

CVE-2004-0609

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions rssh versions 2.0 through 2.1.x
Description The issue allows remote authenticated users to determine the existence of files in a directory outside the jail by expanding command line arguments before entering a chroot jail.
Recommendations For versions 2.0 through 2.1.x, consider restricting access to sensitive directories until a patch is available. As a temporary workaround, limit the ability of remote authenticated users to execute commands that could exploit this issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-0609

Affected Products

Rssh