From f42ea1d7c5f54545aa2ee529142b320062c7d601 Mon Sep 17 00:00:00 2001 From: Remko Lodder Date: Thu, 16 Feb 2006 15:05:13 +0000 Subject: Document rssh -- privilege escalation vulnerability. The port will be marked forbidden due to possible root access. --- security/vuxml/vuln.xml | 33 +++++++++++++++++++++++++++++++++ 1 file changed, 33 insertions(+) (limited to 'security/vuxml/vuln.xml') diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index dec8e3047898..917864722628 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -34,6 +34,39 @@ Note: Please add new entries to the beginning of this file. --> + + rssh -- privilege escalation vulnerability + + + rssh + 2.3.0 + + + + +

Pizzashack reports:

+
+

Max Vozeler has reported a problem whereby rssh can + allow users who have shell access to systems where rssh + is installed (and rssh_chroot_helper is installed SUID) + to gain root access to the system, due to the ability to + chroot to arbitrary locations. There are a lot of + potentially mitigating factors, but to be safe you should + upgrade immediately.

+
+ +
+ + 16050 + CVE-2005-3345 + http://www.pizzashack.org/rssh/security.shtml + + + 2005-12-18 + 2006-02-16 + +
+ tor -- malicious tor server can locate a hidden service -- cgit v1.2.3