CVE-2012-2251

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
11/01/2013
Last modified:
11/04/2025

Description

rssh 2.3.2, as used by Debian, Fedora, and others, when the rsync protocol is enabled, allows local users to bypass intended restricted shell access via a (1) "-e" or (2) "--" command line option.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pizzashack:rssh:2.3.2:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:*:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:*:*:*:*:*:*:*:*