Insufficient sanitization of environment variables passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restrict users to perform only rsync operations, resulting in the execution of arbitrary shell commands.
The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Rssh | Pizzashack | 2.3.4 (including) | 2.3.4 (including) |
Rssh | Ubuntu | bionic | * |
Rssh | Ubuntu | cosmic | * |
Rssh | Ubuntu | trusty | * |
Rssh | Ubuntu | upstream | * |
Rssh | Ubuntu | xenial | * |