Bug 820414 - (CVE-2012-3478) CVE-2012-3478 rssh: circumvention of rssh restrictions using environment variables
CVE-2012-3478 rssh: circumvention of rssh restrictions using environment vari...
Status: NEW
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20120509,repor...
: Security
: 820178 (view as bug list)
Depends On: 820415 820416
Blocks:
  Show dependency treegraph
 
Reported: 2012-05-09 16:47 EDT by Vincent Danen
Modified: 2013-01-11 20:00 EST (History)
3 users (show)

See Also:
Fixed In Version: rssh 2.3.4
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)
rssh-v2.3.4 patch from Derek Martin (7.31 KB, patch)
2012-06-08 05:05 EDT, Jan Lieskovsky
no flags Details | Diff

  None (edit)
Description Vincent Danen 2012-05-09 16:47:58 EDT
A flaw in rssh was reported [1] where a remote user could circumvent rssh restrictions through clever manipulation of environment variables on the ssh command line.

There is no upstream fix, and the upstream author has no intention of fixing the problem, or in continuing to maintain the software, as noted in the vulnerability report.

[1] http://seclists.org/bugtraq/2012/May/35
Comment 1 Vincent Danen 2012-05-09 16:49:01 EDT
Created rssh tracking bugs for this issue

Affects: fedora-all [bug 820415]
Affects: epel-all [bug 820416]
Comment 2 Vincent Danen 2012-05-09 16:50:36 EDT
I think that, unless we want to invest in finding an appropriate fix and maintaining this ourselves, we should remove rssh from Fedora and EPEL, due to upstream's disinterest in maintaining it.
Comment 3 Tomas Hoger 2012-05-10 03:14:43 EDT
*** Bug 820178 has been marked as a duplicate of this bug. ***
Comment 5 Jan Lieskovsky 2012-06-08 05:05:10 EDT
Created attachment 590381 [details]
rssh-v2.3.4 patch from Derek Martin
Comment 7 Tomas Hoger 2012-11-21 09:58:54 EST
(In reply to comment #5)
> Created attachment 590381 [details]
> rssh-v2.3.4 patch from Derek Martin

Source:

http://sourceforge.net/mailarchive/forum.php?thread_name=20120605185223.GI17652%40dragontoe.org&forum_name=rssh-discuss
Comment 9 Tomas Hoger 2012-11-28 03:03:17 EST
The fix is now included in upstream rssh 2.3.4.

http://sourceforge.net/mailarchive/message.php?msg_id=30153369
Comment 10 Fedora Update System 2012-12-19 03:34:53 EST
rssh-2.3.4-1.fc17 has been pushed to the Fedora 17 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 11 Fedora Update System 2013-01-11 20:00:36 EST
rssh-2.3.4-1.fc18 has been pushed to the Fedora 18 stable repository.  If problems still persist, please make note of it in this bug report.

Note You need to log in before you can comment on or make changes to this bug.