LWN.net Logo

rssh: command execution

Package(s):rssh CVE #(s):CVE-2012-2251 CVE-2012-2252
Created:November 28, 2012 Updated:November 28, 2012
Description: From the Debian advisory:

James Clawson discovered that rssh, a restricted shell for OpenSSH to be used with scp/sftp, rdist and cvs, was not correctly filtering command line options. This could be used to force the execution of a remote script and thus allow arbitrary command execution.

Alerts:
Debian DSA-2578-1 2012-11-28
Fedora FEDORA-2012-20109 2012-12-19

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds