CVE Database
/

CVE-2019-3463

Back to search

CVE-2019-3463

Published: Feb 6, 2019

Modified: Sep 17, 2024

PUBLISHED

Description

Insufficient sanitization of arguments passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restrict users to perform only rsync operations, resulting in the execution of arbitrary shell commands.

VendorProductVersions

Debian GNU/Linux

rssh

affected
All versions before 2.3.4-5+deb9u2 and 2.3.4-10

References

DSA-4382
vendor-advisory
x_refsource_DEBIAN
106839
vdb-entry
x_refsource_BID
USN-3946-1
vendor-advisory
x_refsource_UBUNTU
FEDORA-2019-e47add6b2b
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-d1487c13ac
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-bfb407659e
vendor-advisory
x_refsource_FEDORA
GLSA-202007-29
vendor-advisory
x_refsource_GENTOO

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now