Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Debian: DSA-2531-2 Urgent: OpenSSH Remote Code Execution Flaw

debian
Calendar Grey August 15, 2012
Debian Logo
Enhance rssh functionality to address flawed shell access limitations resulting in potential command injection vulnerabilities. Essential update for Debian environments.
Henrik Erkkonen discovered that rssh, a restricted shell for SSH, does not properly restrict shell access

Summary

Henrik Erkkonen discovered that rssh, a restricted shell for SSH, does
not properly restrict shell access.

For the stable distribution (squeeze), this problem has been fixed in
version 2.3.2-13squeeze1.

For the unstable distribution (sid), this problem has been fixed in
version 2.3.3-5.

We recommend that you upgrade your rssh packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: rssh
CVE ID: CVE-2012-3478

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here