<title>rssh: Privilege escalation</title>
Local users could gain root privileges by chrooting into arbitrary
<announced>December 27, 2005</announced>
<revised>December 27, 2005: 01</revised>
rssh is a restricted shell, allowing only a few commands like scp
or sftp. It is often used as a complement to OpenSSH to provide limited
access to users.
Max Vozeler discovered that the rssh_chroot_helper command allows
local users to chroot into arbitrary directories.
A local attacker could exploit this vulnerability to gain root
privileges by chrooting into arbitrary directories.
There is no known workaround at this time.
All rssh users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose &quot;&gt;=app-shells/rssh-2.3.0&quot;</code>
<uri link="">CVE-2005-3345</uri>
<uri link="">rssh security announcement</uri>
