Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.52284
Kategorie:FreeBSD Local Security Checks
Titel:FreeBSD Ports: rssh
Zusammenfassung:The remote host is missing an update to the system; as announced in the referenced advisory.
Beschreibung:Summary:
The remote host is missing an update to the system
as announced in the referenced advisory.

Vulnerability Insight:
The following packages are affected:

rssh, scponly

CVE-2004-1161:
The installed version of rssh does not properly
restrict programs that can be run, which could
allow remote authenticated users to bypass intended
access restrictions and execute arbitrary programs
via (1) rdist -P, (2) rsync, or (3) scp -S.

CVE-2004-1162:
The unison command in scponly before 4.0 does not
properly restrict programs that can be run, which
could allow remote authenticated users to bypass
intended access restrictions and execute arbitrary
programs via the (1) -rshcmd or (2) -sshcmd flags.

Solution:
Update your system with the appropriate patches or
software upgrades.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2004-1161
BugTraq ID: 11792
http://www.securityfocus.com/bid/11792
Bugtraq: 20041202 rssh and scponly arbitrary command execution (Google Search)
http://marc.info/?l=bugtraq&m=110202047507273&w=2
Bugtraq: 20050115 Re: rssh and scponly arbitrary command execution (Google Search)
http://marc.info/?l=bugtraq&m=110581113814623&w=2
http://www.gentoo.org/security/en/glsa/glsa-200412-01.xml
Common Vulnerability Exposure (CVE) ID: CVE-2004-1162
BugTraq ID: 11791
http://www.securityfocus.com/bid/11791
XForce ISS Database: scponly-commandline-command-execution(18362)
https://exchange.xforce.ibmcloud.com/vulnerabilities/18362
CopyrightCopyright (C) 2008 E-Soft Inc.

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.