rssh version 2.3.4 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in allowscp permission that can result in Local command execution. This attack appear to be exploitable via An authorized SSH user with the allowscp permission.
References
Link | Resource |
---|---|
http://seclists.org/fulldisclosure/2021/May/78 | Mailing List Not Applicable Third Party Advisory |
https://esnet-security.github.io/vulnerabilities/20190115_rssh | Exploit Third Party Advisory |
https://lists.debian.org/debian-lts-announce/2019/01/msg00027.html | Mailing List Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HO3MDU3AH5SLYBKHH5PJ6PHC63ASIF42/ | |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KR2OHTHMJVV4DO3HDRFQQZ5JENHDJQEN/ | |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T42YYNWJZG422GATWAHAEK4A24OKY557/ | |
https://security.gentoo.org/glsa/202007-29 | Third Party Advisory |
https://usn.ubuntu.com/3946-1/ | Third Party Advisory |
https://www.debian.org/security/2019/dsa-4377 | Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2019-02-04T21:00:00
Updated: 2021-05-26T23:06:14
Reserved: 2019-01-16T00:00:00
Link: CVE-2019-1000018
JSON object: View
NVD Information
Status : Modified
Published: 2019-02-04T21:29:01.377
Modified: 2023-11-07T03:02:12.580
Link: CVE-2019-1000018
JSON object: View
Redhat Information
No data.
CWE