Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

Gentoo: GLSA-200412-01 Normal: rssh Unrestricted Command Execution

gentoo
Calendar Grey December 3, 2004
Dist Gentoo Esm H88
Gentoo Advisory GLSA 202301-02: Vulnerability in system call handling permits evasion of security mechanisms.
rssh and scponly do not filter command-line options that can be exploited to execute any command, thereby allowing a remote user to completely bypass the restricted shell

Summary

Gentoo Linux Security Advisory GLSA 200412-01 https://security.gentoo.org/ Severity: Normal Title: rssh, scponly: Unrestricted command execution Date: December 03, 2004 Bugs: #72815, #72816 ID: 200412-01

Synopsis ======= rssh and scponly do not filter command-line options that can be exploited to execute any command, thereby allowing a remote user to completely bypass the restricted shell.
Background ========= rssh and scponly are two restricted shells, allowing only a few predefined commands. They are often used as a complement to OpenSSH to provide access to remote users without providing any remote execution privileges.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-misc/scpon...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns


Warning: Undefined array key "advisory_info" in /var/www/www.linuxsecurity.com-443/html/tmp/regularlabs/custom_php/4093450_4c9dbbdde36eef04251a4ced7eac4df9 on line 11

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here