Security Advisory

CVE-2019-3464

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2019-02-06 19:00:00
Last updated 2024-09-17 04:29:35
Assigner debian
State PUBLISHED

Description

Insufficient sanitization of environment variables passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restrict users to perform only rsync operations, resulting in the execution of arbitrary shell commands.