Vulnerabilities > CVE-2005-3345 - Local Privilege Escalation vulnerability in RSSH RSSH_CHROOT_HELPER

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
rssh
nessus

Summary

rssh 2.0.0 through 2.2.3 allows local users to bypass access restrictions and gain root privileges by using the rssh_chroot_helper command to chroot to an external directory.

Vulnerable Configurations

Part Description Count
Application
Rssh
6

Nessus

  • NASL familyGentoo Local Security Checks
    NASL idGENTOO_GLSA-200512-15.NASL
    descriptionThe remote host is affected by the vulnerability described in GLSA-200512-15 (rssh: Privilege escalation) Max Vozeler discovered that the rssh_chroot_helper command allows local users to chroot into arbitrary directories. Impact : A local attacker could exploit this vulnerability to gain root privileges by chrooting into arbitrary directories. Workaround : There is no known workaround at this time.
    last seen2020-06-01
    modified2020-06-02
    plugin id20356
    published2005-12-30
    reporterThis script is Copyright (C) 2005-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/20356
    titleGLSA-200512-15 : rssh: Privilege escalation
  • NASL familyFreeBSD Local Security Checks
    NASL idFREEBSD_PKG_E34D0C2E9EFB11DAB410000E0C2E438A.NASL
    descriptionPizzashack reports : Max Vozeler has reported a problem whereby rssh can allow users who have shell access to systems where rssh is installed (and rssh_chroot_helper is installed SUID) to gain root access to the system, due to the ability to chroot to arbitrary locations. There are a lot of potentially mitigating factors, but to be safe you should upgrade immediately.
    last seen2020-06-01
    modified2020-06-02
    plugin id21525
    published2006-05-13
    reporterThis script is Copyright (C) 2006-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/21525
    titleFreeBSD : rssh -- privilege escalation vulnerability (e34d0c2e-9efb-11da-b410-000e0c2e438a)