LWN.net Logo

rssh, scponly: unrestricted command execution

Package(s):rssh, scponly CVE #(s):
Created:December 3, 2004 Updated:December 8, 2004
Description: Jason Wies discovered that when receiving an authorized command from an authorized user, rssh and scponly do not filter command-line options that can be used to execute any command on the target host. Using a malicious command, it is possible for a remote authenticated user to execute any command (or upload and execute any file) on the target machine with user rights, effectively bypassing any restriction of scponly or rssh. See this Bugtraq post for more details.
Alerts:
Gentoo 200412-01 2004-12-03

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds