FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2005-3345

This CVE name corresponds to:

Entered Topic
2006-02-16 rssh -- privilege escalation vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2005-3345
Phase Assigned(20051027)

Description

rssh 2.0.0 through 2.2.3 allows local users to bypass access restrictions and gain root privileges by using the rssh_chroot_helper command to chroot to an external directory.

References

Source Reference
CONFIRM http://www.pizzashack.org/rssh/security.shtml
CONFIRM http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=344424
GENTOO GLSA-200512-15
BID 16050
SECUNIA 18224
SECUNIA 18237
SREASON 308
XF rssh-chroot-gain-privileges(23854)