util.c in rssh 2.3.0 in Debian GNU/Linux does not use braces to make a block, which causes a check for CVS to always succeed and allows rsync and rdist to bypass intended access restrictions in rssh.conf.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Rssh | Rssh | 2.3.0 (including) | 2.3.0 (including) |