Lucene search

K
ubuntucveUbuntu.comUB:CVE-2004-1161
HistoryJan 10, 2005 - 12:00 a.m.

CVE-2004-1161

2005-01-1000:00:00
ubuntu.com
ubuntu.com
8

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.02

Percentile

88.9%

rssh 2.2.2 and earlier does not properly restrict programs that can be run,
which could allow remote authenticated users to bypass intended access
restrictions and execute arbitrary programs via (1) rdist -P, (2) rsync, or
(3) scp -S.

OSVersionArchitecturePackageVersionFilename
ubuntu6.06noarchrssh< 2.3.0-1.1UNKNOWN
ubuntu6.10noarchrssh< 2.3.0-1.1UNKNOWN
ubuntu7.04noarchrssh< 2.3.0-1.1UNKNOWN

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.02

Percentile

88.9%