SB2017042415 - Multiple vulnerabilities in lshell
Published: April 24, 2017 Updated: October 22, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 vulnerabilities.
1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2016-6902)
The vulnerability allows a remote authenticated user to execute arbitrary code.
lshell 0.9.16 allows remote authenticated users to break out of a limited shell and execute arbitrary commands.
2) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2016-6903)
The vulnerability allows a remote authenticated user to execute arbitrary code.
lshell 0.9.16 allows remote authenticated users to break out of a limited shell and execute arbitrary commands.
Remediation
Install update from vendor's website.
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1369345
- https://github.com/ghantoos/lshell/commit/a686f71732a3d0f16df52ef46ab8a49ee0083c68
- https://github.com/ghantoos/lshell/issues/147
- https://github.com/advisories/GHSA-f3r7-j2g2-9mjw
- https://github.com/ghantoos/lshell/releases/tag/0.10
- https://github.com/ghantoos/lshell/commit/e72dfcd1f258193f9aaea3591ecbdaed207661a0
- https://github.com/ghantoos/lshell/issues/149
- https://github.com/ghantoos/lshell/pull/153/commits/a686f71732a3d0f16df52ef46ab8a49ee0083c68
- https://github.com/advisories/GHSA-vw92-qfr4-w98m