CVE-2012-2252 Information

Description

Incomplete blacklist vulnerability in rssh before 2.3.4 when the rsync protocol is enabled allows local users to bypass intended restricted shell access via the –rsh command line option.

Reference

http://archives.neohapsis.com/archives/bugtraq/2012-11/0101.html http://osvdb.org/87926 http://secunia.com/advisories/51307 http://secunia.com/advisories/51343 http://www.debian.org/security/2012/dsa-2578 http://www.openwall.com/lists/oss-security/2012/11/27/15 http://www.openwall.com/lists/oss-security/2012/11/28/2 http://www.openwall.com/lists/oss-security/2012/11/28/3 http://www.securityfocus.com/bid/56708 https://bugzilla.redhat.com/show_bug.cgi?id=880177 https://exchange.xforce.ibmcloud.com/vulnerabilities/80335

Share on: