|
|
| |
|
| |
rssh: command execution
| Package(s): | rssh |
CVE #(s): | CVE-2012-2251
CVE-2012-2252
|
| Created: | November 28, 2012 |
Updated: | November 28, 2012 |
| Description: |
From the Debian advisory:
James Clawson discovered that rssh, a restricted shell for OpenSSH to be used
with scp/sftp, rdist and cvs, was not correctly filtering command line options.
This could be used to force the execution of a remote script and thus allow
arbitrary command execution. |
| Alerts: |
|
( Log in to post comments)
|
|
|