From 3cf7c3ef441822c889356fd1812ebf2944a59851 Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Tue, 25 Aug 2020 10:45:55 +0100 Subject: gentoo resync : 25.08.2020 --- metadata/glsa/glsa-202007-29.xml | 59 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 59 insertions(+) create mode 100644 metadata/glsa/glsa-202007-29.xml (limited to 'metadata/glsa/glsa-202007-29.xml') diff --git a/metadata/glsa/glsa-202007-29.xml b/metadata/glsa/glsa-202007-29.xml new file mode 100644 index 000000000000..07c32a1b7c2f --- /dev/null +++ b/metadata/glsa/glsa-202007-29.xml @@ -0,0 +1,59 @@ + + + + rssh: Multiple vulnerabilities + Multiple vulnerabilities have been found in rssh, the worst of + which could result in the arbitrary execution of code. + + rssh + 2020-07-27 + 2020-07-27 + 699842 + remote + + + 2.3.4_p3 + + + +

rssh is a restricted shell, allowing only a few commands like scp or + sftp. It is often used as a complement to OpenSSH to provide limited + access to users. +

+
+ +

Multiple vulnerabilities have been discovered in rssh. Please review the + CVE identifiers referenced below for details. +

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

Gentoo has discontinued support for rssh. We recommend that users + unmerge rssh: +

+ + + # emerge --unmerge "app-shells/rssh" + + +

NOTE: The Gentoo developer(s) maintaining rssh have discontinued support + at this time. It may be possible that a new Gentoo developer will update + rssh at a later date. OpenSSH (net-misc/openssh) may be able to provide + similar functionality using its extensive configuration. +

+
+ + + CVE-2019-1000018 + + CVE-2019-3463 + CVE-2019-3464 + + b-man + sam_c +
-- cgit v1.2.3