CVE Vulnerabilities

CVE-2004-1161

Published: Jan 10, 2005 | Modified: Oct 18, 2016
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

rssh 2.2.2 and earlier does not properly restrict programs that can be run, which could allow remote authenticated users to bypass intended access restrictions and execute arbitrary programs via (1) rdist -P, (2) rsync, or (3) scp -S.

Affected Software

Name Vendor Start Version End Version
Rssh Rssh 2.0 2.0
Rssh Rssh 2.1 2.1
Rssh Rssh 2.2 2.2
Rssh Rssh 2.2.1 2.2.1
Rssh Rssh 2.2.2 2.2.2
Rssh Ubuntu dapper *
Rssh Ubuntu devel *
Rssh Ubuntu edgy *
Rssh Ubuntu feisty *

References