CVE-2019-1000018: Command Injection
Last updated 25 August 2025
Other sources
rssh version 2.3.4 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in allowscp permission that can result in Local command execution. This attack appear to be exploitable via An authorized SSH user with the allowscp permission.
— Launchpad
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-1000018?
CVE-2019-1000018 has been rated as a critical vulnerability due to its potential for local command execution.
How do I fix CVE-2019-1000018?
To mitigate CVE-2019-1000018, upgrade rssh to version 2.3.4-9 or higher.
Who is affected by CVE-2019-1000018?
CVE-2019-1000018 affects users of rssh version 2.3.4 running on Debian and other Linux distributions.
What type of vulnerability is CVE-2019-1000018?
CVE-2019-1000018 is classified as a Command Injection vulnerability due to improper neutralization of special elements.
Can CVE-2019-1000018 be exploited remotely?
CVE-2019-1000018 requires an authorized SSH user to exploit the vulnerability, so remote exploitation is not possible.