CVEs (7)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraRssh+1 moreJun 17, 2026 Feb 6, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Insufficient sanitization of environment variables passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restrict users to perform only rsync operations, resulting in the execution o...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraRssh+1 moreJun 17, 2026 Feb 6, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Insufficient sanitization of arguments passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restrict users to perform only rsync operations, resulting in the execution of arbitrary...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraRssh+1 moreJun 17, 2026 Feb 4, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 rssh version 2.3.4 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in allowscp permission that can result in Local command execution. This attack appea...Show more |
Incomplete blacklist vulnerability in rssh before 2.3.4, when the rsync protocol is enabled, allows local users to bypass intended restricted shell access via the --rsh command line option. |
rssh 2.3.2, as used by Debian, Fedora, and others, when the rsync protocol is enabled, allows local users to bypass intended restricted shell access via a (1) "-e" or (2) "--" command line option. |
rssh 2.3.3 and earlier allows local users to bypass intended restricted shell access via crafted environment variables in the command line. |
Format string vulnerability in log.c in rssh before 2.2.2 allows remote authenticated users to execute arbitrary code. |