rssh: Access restriction bypass Multiple vulnerabilities have been found in rssh, allowing local attackers to bypass access restrictions. rssh 2013-11-28 2013-11-28 415255 445166 local 2.3.4 2.3.4

rssh is a restricted shell, allowing only a few commands like scp or sftp. It is often used as a complement to OpenSSH to provide limited access to users.

Multiple command line parsing and validation vulnerabilities have been discovered in rssh. Please review the CVE identifiers referenced below for details.

Multiple parsing and validation vulnerabilities can cause the restrictions set up by rssh to be bypassed.

There is no known workaround at this time.

All rssh users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=app-shells/rssh-2.3.4"
CVE-2012-2252 CVE-2012-3478 underling BlueKnight