rssh 2.2.2 and earlier does not properly restrict programs that can be run, which could allow remote authenticated users to bypass intended access restrictions and execute arbitrary programs via (1) rdist -P, (2) rsync, or (3) scp -S.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-08T00:39:00.899Z
Reserved: 2004-12-09T00:00:00
Link: CVE-2004-1161

No data.

Status : Modified
Published: 2005-01-10T05:00:00.000
Modified: 2024-11-20T23:50:14.900
Link: CVE-2004-1161

No data.