PT-2019-1910 · Rsync+1 · Rsync+1

Nick Cleaton

·

Published

2019-02-02

·

Updated

2021-07-21

·

CVE-2019-3464

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions rsync (affected versions not specified)
Description The issue is related to insufficient sanitization of environment variables passed to rsync, which can bypass restrictions imposed by rssh, a restricted shell. This allows for the execution of arbitrary shell commands. The vulnerability is associated with errors in input validation. Exploitation can enable a remote attacker to execute arbitrary commands.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Initialization

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-01578
CVE-2019-3464
DLA-1660-1
DLA-1660-2
DSA-4382-1
USN-3946-1

Affected Products

Ubuntu
Rsync