PT-2019-1685 · None+1 · Rssh+1

Published

2019-01-30

·

Updated

2025-03-19

·

CVE-2019-1000018

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions rssh version 2.3.4
Description The issue is related to a command injection vulnerability in the allowscp permission, which can result in local command execution. This can be exploited by an authorized SSH user with the allowscp permission. The vulnerability is due to the lack of input data sanitization, allowing an attacker to execute arbitrary shell commands.
Recommendations For version 2.3.4, consider restricting the use of the allowscp permission until a patch is available. As a temporary workaround, limit the access of authorized SSH users to minimize the risk of exploitation.

Exploit

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-01279
CVE-2019-1000018
DLA-1650-1
DSA-4377-1
DSA-4377-2
DSA-4377-3
USN-3946-1

Affected Products

Ubuntu
Rssh