Summary
The remote host is missing an update to the system as announced in the referenced advisory.
Solution
Update your system with the appropriate patches or software upgrades.
http://marc.theaimsgroup.com/?l=bugtraq&m=110202047507273 http://www.vuxml.org/freebsd/f11b219a-44b6-11d9-ae2f-021106004fd6.html
Insight
The following packages are affected:
rssh
scponly
CVE-2004-1161:
The installed version of rssh does not properly
restrict programs that can be run, which could
allow remote authenticated users to bypass intended access restrictions and execute arbitrary programs via (1) rdist -P, (2) rsync, or (3) scp -S.
CVE-2004-1162:
The unison command in scponly before 4.0 does not
properly restrict programs that can be run, which
could allow remote authenticated users to bypass
intended access restrictions and execute arbitrary programs via the (1) -rshcmd or (2) -sshcmd flags.
Severity
Classification
-
CVE CVE-2004-1161, CVE-2004-1162 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities