UBUNTU-CVE-2019-1000018
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-1000018
UBUNTU-CVE-2019-1000018
Summary:
Details: rssh version 2.3.4 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in allowscp permission that can result in Local command execution. This attack appear to be exploitable via An authorized SSH user with the allowscp permission.
References: https://ubuntu.com/security/CVE-2019-1000018, https://sourceforge.net/p/rssh/mailman/message/36519118/, https://salsa.debian.org/debian/rssh/commit/3536b6d8e77ece7d66215fe1d08cf633d6b1c97b, https://esnet-security.github.io/vulnerabilities/20190115_rssh, https://ubuntu.com/security/notices/USN-3946-1, https://www.cve.org/CVERecord?id=CVE-2019-1000018
Affected packages
Package
Name: rssh
Purl: pkg:deb/ubuntu/[email protected]+deb8u2ubuntu0.14.04.2?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
