The HTTPS fallback implementation in Shell In A Box (aka shellinabox) before 2.19 makes it easier for remote attackers to conduct DNS rebinding attacks via the /plain URL.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Fedora | Fedoraproject | 22 (including) | 22 (including) |
| Fedora | Fedoraproject | 23 (including) | 23 (including) |
| Shellinabox | Ubuntu | trusty | * |
| Shellinabox | Ubuntu | vivid | * |
| Shellinabox | Ubuntu | wily | * |