4.4
CVSSv2

CVE-2012-2252

Published: 11/01/2013 Updated: 29/08/2017
CVSS v2 Base Score: 4.4 | Impact Score: 6.4 | Exploitability Score: 3.4
VMScore: 392
Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Incomplete blacklist vulnerability in rssh prior to 2.3.4, when the rsync protocol is enabled, allows local users to bypass intended restricted shell access via the --rsh command line option.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

pizzashack rssh 2.2.2

pizzashack rssh 2.2.1

pizzashack rssh 2.0.0

pizzashack rssh 2.3.1

pizzashack rssh 2.3.0

pizzashack rssh 2.2.3

pizzashack rssh 2.0.2

pizzashack rssh 2.0.1

pizzashack rssh 2.1.0

pizzashack rssh 2.1.1

pizzashack rssh

pizzashack rssh 2.3.2

pizzashack rssh 2.0.4

pizzashack rssh 2.0.3

Vendor Advisories

Debian Bug report logs - #919623 rssh: CVE-2019-1000018: Remote code execution in scp support Package: rssh; Maintainer for rssh is Russ Allbery <rra@debianorg>; Source for rssh is src:rssh (PTS, buildd, popcon) Reported by: Russ Allbery <rra@debianorg> Date: Fri, 18 Jan 2019 03:27:02 UTC Severity: grave Tags: sec ...