util.c in rssh 2.3.0 in Debian GNU/Linux does not use braces to make a block, which causes a check for CVS to always succeed and allows rsync and rdist to bypass intended access restrictions in rssh.conf.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Rssh |
Rssh |
2.3.0 |
2.3.0 |
References