Alerts This Week
Warning Icon 1 562
Alerts This Week
Warning Icon 1 562

Gentoo: GLSA-200410-28 Severe: rssh Format String Vulnerability Risk

gentoo
Calendar Grey October 27, 2004
Dist Gentoo Esm H88
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Adviso
rssh is vulnerable to a format string vulnerability that allows arbitrary execution of code with the rights of the connected user, thereby bypassing rssh restrictions

Summary

Gentoo Linux Security Advisory GLSA 200410-28 https://security.gentoo.org/ Severity: High Title: rssh: Format string vulnerability Date: October 27, 2004 Bugs: #66988 ID: 200410-28

Synopsis ======= rssh is vulnerable to a format string vulnerability that allows arbitrary execution of code with the rights of the connected user, thereby bypassing rssh restrictions.
Background ========= rssh is a restricted shell, allowing only a few commands like scp or sftp. It is often used as a complement to OpenSSH to provide limited access to users.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-shells/rssh < 2.2.2 >= 2.2.2
========== Florian Schilhabel f...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns


Warning: Undefined array key "advisory_info" in /var/www/www.linuxsecurity.com-443/html/tmp/regularlabs/custom_php/3430158_4c9dbbdde36eef04251a4ced7eac4df9 on line 11

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here