SB2012083104 - Permissions, Privileges, and Access Controls in rssh.sourceforge.net rssh
Published: August 31, 2012 Updated: August 11, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2012-3478)
CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote non-authenticated attacker to manipulate data.
rssh 2.3.3 and earlier allows local users to bypass intended restricted shell access via crafted environment variables in the command line.
Remediation
Install update from vendor's website.
References
- http://archives.neohapsis.com/archives/bugtraq/2012-05/0036.html
- http://archives.neohapsis.com/archives/bugtraq/2012-11/0101.html
- http://secunia.com/advisories/50272
- http://sourceforge.net/mailarchive/message.php?msg_id=29235647
- http://www.debian.org/security/2012/dsa-2530
- http://www.openwall.com/lists/oss-security/2012/08/10/7
- http://www.openwall.com/lists/oss-security/2012/08/11/3
- http://www.openwall.com/lists/oss-security/2012/11/28/3
- http://www.securityfocus.com/bid/53430