rssh: Privilege escalation Local users could gain root privileges by chrooting into arbitrary directories. rssh 2005-12-27 2005-12-27 115082 local 2.3.0 2.3.0

rssh is a restricted shell, allowing only a few commands like scp or sftp. It is often used as a complement to OpenSSH to provide limited access to users.

Max Vozeler discovered that the rssh_chroot_helper command allows local users to chroot into arbitrary directories.

A local attacker could exploit this vulnerability to gain root privileges by chrooting into arbitrary directories.

There is no known workaround at this time.

All rssh users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=app-shells/rssh-2.3.0"
CVE-2005-3345 rssh security announcement koon DerCorny DerCorny