Vulnerability Description
rssh 2.0 through 2.1.x expands command line arguments before entering a chroot jail, which allows remote authenticated users to determine the existence of files in a directory outside the jail.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rssh | Rssh | 2.0 |
References
- http://marc.info/?l=bugtraq&m=108787373022844&w=2
- http://www.securityfocus.com/bid/10574PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16470
- http://marc.info/?l=bugtraq&m=108787373022844&w=2
- http://www.securityfocus.com/bid/10574PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16470
FAQ
What is CVE-2004-0609?
CVE-2004-0609 is a vulnerability with a CVSS score of 5.0 (MEDIUM). rssh 2.0 through 2.1.x expands command line arguments before entering a chroot jail, which allows remote authenticated users to determine the existence of files in a directory outside the jail.
How severe is CVE-2004-0609?
CVE-2004-0609 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-0609?
Check the references section above for vendor advisories and patch information. Affected products include: Rssh Rssh.