UBUNTU-CVE-2019-3463
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-3463
UBUNTU-CVE-2019-3463
Summary:
Details: Insufficient sanitization of arguments passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restrict users to perform only rsync operations, resulting in the execution of arbitrary shell commands.
References: https://ubuntu.com/security/CVE-2019-3463, https://tracker.debian.org/news/1026713/accepted-rssh-234-5deb9u2-source-amd64-into-stable-embargoed-stable/, https://salsa.debian.org/debian/rssh/commit/3536b6d8e77ece7d66215fe1d08cf633d6b1c97b, https://ubuntu.com/security/notices/USN-3946-1, https://www.cve.org/CVERecord?id=CVE-2019-3463
Affected packages
Package
Name: rssh
Purl: pkg:deb/ubuntu/[email protected]+deb8u2ubuntu0.14.04.2?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
