RSSH RSSH_CHROOT_HELPER Local Privilege Escalation Vulnerability
BID:16050
Info
RSSH RSSH_CHROOT_HELPER Local Privilege Escalation Vulnerability
| Bugtraq ID: | 16050 |
| Class: | Design Error |
| CVE: |
CVE-2005-3345 |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 23 2005 12:00AM |
| Updated: | Dec 23 2005 12:00AM |
| Credit: | Discovered by Max Vozeler. |
| Vulnerable: |
rssh rssh 2.2.3 rssh rssh 2.2.2 rssh rssh 2.2.1 rssh rssh 2.2 rssh rssh 2.1 rssh rssh 2.0 |
| Not Vulnerable: |
rssh rssh 2.3.1 rssh rssh 2.3 |
Discussion
RSSH RSSH_CHROOT_HELPER Local Privilege Escalation Vulnerability
rssh is prone to a local privilege escalation vulnerability.
Local attackers can gain superuser privileges due to having the ability to chroot to arbitrary locations as the application facilitates subverting the chroot location.
rssh versions 2.0.0 to 2.2.3 are vulnerable to this issue.
rssh is prone to a local privilege escalation vulnerability.
Local attackers can gain superuser privileges due to having the ability to chroot to arbitrary locations as the application facilitates subverting the chroot location.
rssh versions 2.0.0 to 2.2.3 are vulnerable to this issue.
Exploit / POC
RSSH RSSH_CHROOT_HELPER Local Privilege Escalation Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
RSSH RSSH_CHROOT_HELPER Local Privilege Escalation Vulnerability
Solution:
Gentoo has released an advisory to address this issue. Gentoo users may apply upgrades by running the following commands as the superuser:
emerge --sync
emerge --ask --oneshot --verbose ">=app-shells/rssh-2.3.0"
The vendor has released rssh 2.3.0 to address this issue.
The vendor has advised users to upgrade to rssh 2.3.1 due to a bug in rssh 2.3.0.
rssh rssh 2.0
rssh rssh 2.1
rssh rssh 2.2
rssh rssh 2.2.1
rssh rssh 2.2.2
rssh rssh 2.2.3
Solution:
Gentoo has released an advisory to address this issue. Gentoo users may apply upgrades by running the following commands as the superuser:
emerge --sync
emerge --ask --oneshot --verbose ">=app-shells/rssh-2.3.0"
The vendor has released rssh 2.3.0 to address this issue.
The vendor has advised users to upgrade to rssh 2.3.1 due to a bug in rssh 2.3.0.
rssh rssh 2.0
rssh rssh 2.1
rssh rssh 2.2
rssh rssh 2.2.1
rssh rssh 2.2.2
rssh rssh 2.2.3
References
RSSH RSSH_CHROOT_HELPER Local Privilege Escalation Vulnerability
References:
References:
- rssh Product Page (rssh)
- rssh security implications (rssh)
- rssh: root privilege escalation flaw (Derek Martin
)