scponly Local Arbitrary Command Execution Weakness
BID:26900
Info
scponly Local Arbitrary Command Execution Weakness
| Bugtraq ID: | 26900 |
| Class: | Design Error |
| CVE: |
CVE-2007-6350 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 17 2007 12:00AM |
| Updated: | Apr 13 2015 10:07PM |
| Credit: | Joachim Breitner discovered this issue. |
| Vulnerable: |
scponly scponly 4.6 scponly scponly 4.0 Redhat Fedora 7 Gentoo Linux Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: | |
Discussion
scponly Local Arbitrary Command Execution Weakness
The 'scponly' program is prone to a weakness that can allow attackers to execute arbitrary commands.
Attackers with scponly access can exploit this issue to bypass scponly security restrictions. Successful attacks could compromise affected computers.
This issue affects scponly 4.6; other versions may also be affected.
The 'scponly' program is prone to a weakness that can allow attackers to execute arbitrary commands.
Attackers with scponly access can exploit this issue to bypass scponly security restrictions. Successful attacks could compromise affected computers.
This issue affects scponly 4.6; other versions may also be affected.
Exploit / POC
scponly Local Arbitrary Command Execution Weakness
Attackers with scponly access can exploit this issue using applications such as svn, svnserve, rsync, or unison.
Attackers with scponly access can exploit this issue using applications such as svn, svnserve, rsync, or unison.
Solution / Fix
scponly Local Arbitrary Command Execution Weakness
Solution:
Fixes are available to address this issue. Please see the references for more information.
scponly scponly 4.0
scponly scponly 4.6
Solution:
Fixes are available to address this issue. Please see the references for more information.
scponly scponly 4.0
-
Debian scponly_4.6-1.1.diff.gz
http://ftp.us.debian.org/debian/pool/main/s/scponly/scponly_4.6-1.1.di ff.gz
scponly scponly 4.6
-
Debian scponly_4.6-1.1.diff.gz
http://ftp.us.debian.org/debian/pool/main/s/scponly/scponly_4.6-1.1.di ff.gz
References
scponly Local Arbitrary Command Execution Weakness
References:
References:
- Debian Bug report logs - #437148 "svn", "svnserve", "unison", "rsync" passthroug (Debian)
- Vendor Homepage (scponly)
- View of /scponly/SECURITY (scponly)