|
|
| |
|
| |
rssh, scponly: unrestricted command execution
| Package(s): | rssh, scponly |
CVE #(s): | |
| Created: | December 3, 2004 |
Updated: | December 8, 2004 |
| Description: |
Jason Wies discovered that when receiving an authorized command from an
authorized user, rssh and scponly do not filter command-line options
that can be used to execute any command on the target host. Using a
malicious command, it is possible for a remote authenticated user to
execute any command (or upload and execute any file) on the target machine
with user rights, effectively bypassing any restriction of scponly or
rssh. See
this Bugtraq post for more details. |
| Alerts: |
|
( Log in to post comments)
|
|
|