4.4
CVSSv2

CVE-2012-2251

Published: 11/01/2013 Updated: 29/08/2017
CVSS v2 Base Score: 4.4 | Impact Score: 6.4 | Exploitability Score: 3.4
VMScore: 392
Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

rssh 2.3.2, as used by Debian, Fedora, and others, when the rsync protocol is enabled, allows local users to bypass intended restricted shell access via a (1) "-e" or (2) "--" command line option.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

pizzashack rssh 2.3.2

Vendor Advisories

Debian Bug report logs - #919623 rssh: CVE-2019-1000018: Remote code execution in scp support Package: rssh; Maintainer for rssh is Russ Allbery <rra@debianorg>; Source for rssh is src:rssh (PTS, buildd, popcon) Reported by: Russ Allbery <rra@debianorg> Date: Fri, 18 Jan 2019 03:27:02 UTC Severity: grave Tags: sec ...