Summary
The remote host is missing updates announced in
advisory GLSA 200412-01.
Solution
All scponly users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose '>=net-misc/scponly-4.0'
All rssh users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose '>=app-shells/rssh/rssh-2.2.3'
http://www.securityspace.com/smysecure/catid.html?in=GLSA%20200412-01 http://bugs.gentoo.org/show_bug.cgi?id=72815
http://bugs.gentoo.org/show_bug.cgi?id=72816
http://www.securityfocus.com/archive/1/383046/2004-11-30/2004-12-06/0
Insight
rssh and scponly do not filter command-line options that can be exploited to execute any command, thereby allowing a remote user to completely bypass the restricted shell.
Severity
Classification
-
CVE CVE-2004-1161, CVE-2004-1162 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities