PT-2013-1086 · Rssh · Rssh
James Clawson
·
Published
2013-01-11
·
Updated
2017-08-29
·
CVE-2012-2251
CVSS v2.0
4.4
Medium
| Vector | AV:L/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
rssh version 2.3.2
Description
The issue allows local users to bypass intended restricted shell access. This can be achieved via the
-e or -- command line option. Multiple vulnerabilities in the rssh package may lead to a breach of confidentiality, integrity, and availability of protected information. A local attacker can exploit these vulnerabilities.Recommendations
For rssh version 2.3.2, consider restricting access to the
-e and -- command line options as a temporary workaround until a patch is available. Restrict the use of the rsync protocol to minimize the risk of exploitation.Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rssh