Debian GNU/Linux Rssh Security Bypass Vulnerability
BID:18999
Info
Debian GNU/Linux Rssh Security Bypass Vulnerability
| Bugtraq ID: | 18999 |
| Class: | Design Error |
| CVE: |
CVE-2006-1320 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 17 2006 12:00AM |
| Updated: | Aug 24 2006 08:34PM |
| Credit: | Russ Allbery is credited with the discovery of this issue. |
| Vulnerable: |
Debian rssh 2.3.0-1 |
| Not Vulnerable: |
Debian rssh sid 2.3.0-1.1 Debian rssh sarge 2.2.3-1 |
Discussion
Debian GNU/Linux Rssh Security Bypass Vulnerability
A programming error in the 'util.c' file of the rssh package in Debian GNU/Linux allows rdist and rsync to bypass security.
This vulnerability may facilitate privilege escalation, because the error allows rssh's check for CVS to always succeed. An attacker could use this vulnerability to their advantage and bypass existing security limitations and access controls.
A programming error in the 'util.c' file of the rssh package in Debian GNU/Linux allows rdist and rsync to bypass security.
This vulnerability may facilitate privilege escalation, because the error allows rssh's check for CVS to always succeed. An attacker could use this vulnerability to their advantage and bypass existing security limitations and access controls.
Exploit / POC
Debian GNU/Linux Rssh Security Bypass Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Debian GNU/Linux Rssh Security Bypass Vulnerability
Solution:
Debian GNU/Linux has released fixed builds of the rssh package.
Users should use the 'apt-get' utility to ensure that a fixed version of the affected package is installed.
Solution:
Debian GNU/Linux has released fixed builds of the rssh package.
Users should use the 'apt-get' utility to ensure that a fixed version of the affected package is installed.
References
Debian GNU/Linux Rssh Security Bypass Vulnerability
References:
References:
- Debian Bug report logs - #346322 (Debian)
- Debian Homepage (Debian)