PT-2006-2329 · Rssh · Rssh

Russ Allbery

·

Published

2006-03-20

·

Updated

2017-07-20

·

CVE-2006-1320

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions rssh version 2.3.0
Description The issue is related to a problem in the util.c file of rssh, where the lack of braces to define a block causes a check to always succeed, allowing rsync and rdist to bypass intended access restrictions defined in rssh.conf.
Recommendations For rssh version 2.3.0, consider modifying the util.c file to properly use braces and define blocks, ensuring that access restrictions in rssh.conf are correctly enforced. As a temporary workaround, restrict access to rsync and rdist until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-1320
DSA-1109

Affected Products

Rssh