First published: Fri Dec 10 2004(Updated: )
rssh 2.2.2 and earlier does not properly restrict programs that can be run, which could allow remote authenticated users to bypass intended access restrictions and execute arbitrary programs via (1) rdist -P, (2) rsync, or (3) scp -S.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Rssh | =2.2 | |
Rssh | =2.2.2 | |
Rssh | =2.1 | |
Rssh | =2.0 | |
Rssh | =2.2.1 | |
Gentoo Linux |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1161 is considered a high severity vulnerability due to its potential to allow remote authenticated users to bypass access restrictions.
To fix CVE-2004-1161, upgrade to rssh version 2.2.3 or later, which addresses this vulnerability.
CVE-2004-1161 affects rssh versions 2.0, 2.1, 2.2, and 2.2.1.
Yes, CVE-2004-1161 can be exploited remotely by authenticated users, allowing them to execute arbitrary programs.
The implications of CVE-2004-1161 include potential unauthorized access and control over the system, leading to data compromise.