rssh contains a flaw that is triggered during the validation of the --rsh command line option. This will allow a local attacker to bypass the local command filter, reducing restrictions placed on the commands that can be executed.
Classification
Location:
Local Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Solution:
Upgrade
Exploit:
Exploit Unknown
Disclosure:
Vendor Verified
OSVDB:
Authentication Required
Solution
It has been reported that this issue has been fixed. Upgrade to version 2.3.4, or higher, to address this vulnerability.