Note: This is a public test instance of Red Hat Bugzilla. The data contained within is a snapshot of the live data so any changes you make will not be reflected in the production Bugzilla. Email is disabled so feel free to test any aspect of the site that you want. File any problems you find or give feedback at bugzilla.redhat.com.

Bug 820414 (CVE-2012-3478)

Summary: CVE-2012-3478 rssh: circumvention of rssh restrictions using environment variables
Product: [Other] Security Response Reporter: Vincent Danen <vdanen>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED UPSTREAM QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: jlieskov, metherid, xavier
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: rssh 2.3.4 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2019-06-10 10:58:33 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 820415, 820416    
Bug Blocks:    
Attachments:
Description Flags
rssh-v2.3.4 patch from Derek Martin none

Description Vincent Danen 2012-05-09 20:47:58 UTC
A flaw in rssh was reported [1] where a remote user could circumvent rssh restrictions through clever manipulation of environment variables on the ssh command line.

There is no upstream fix, and the upstream author has no intention of fixing the problem, or in continuing to maintain the software, as noted in the vulnerability report.

[1] http://seclists.org/bugtraq/2012/May/35

Comment 1 Vincent Danen 2012-05-09 20:49:01 UTC
Created rssh tracking bugs for this issue

Affects: fedora-all [bug 820415]
Affects: epel-all [bug 820416]

Comment 2 Vincent Danen 2012-05-09 20:50:36 UTC
I think that, unless we want to invest in finding an appropriate fix and maintaining this ourselves, we should remove rssh from Fedora and EPEL, due to upstream's disinterest in maintaining it.

Comment 3 Tomas Hoger 2012-05-10 07:14:43 UTC
*** Bug 820178 has been marked as a duplicate of this bug. ***

Comment 5 Jan Lieskovsky 2012-06-08 09:05:10 UTC
Created attachment 590381 [details]
rssh-v2.3.4 patch from Derek Martin

Comment 7 Tomas Hoger 2012-11-21 14:58:54 UTC
(In reply to comment #5)
> Created attachment 590381 [details]
> rssh-v2.3.4 patch from Derek Martin

Source:

http://sourceforge.net/mailarchive/forum.php?thread_name=20120605185223.GI17652%40dragontoe.org&forum_name=rssh-discuss

Comment 9 Tomas Hoger 2012-11-28 08:03:17 UTC
The fix is now included in upstream rssh 2.3.4.

http://sourceforge.net/mailarchive/message.php?msg_id=30153369

Comment 10 Fedora Update System 2012-12-19 08:34:53 UTC
rssh-2.3.4-1.fc17 has been pushed to the Fedora 17 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 11 Fedora Update System 2013-01-12 01:00:36 UTC
rssh-2.3.4-1.fc18 has been pushed to the Fedora 18 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 12 Product Security DevOps Team 2019-06-10 10:58:33 UTC
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.