Amazon Linux AMI update for rssh



Risk High
Patch available YES
Number of vulnerabilities 3
CVE-ID CVE-2019-1000018
CVE-2019-3463
CVE-2019-3464
CWE-ID CWE-78
Exploitation vector Network
Public exploit Public exploit code for vulnerability #1 is available.
Vulnerable software
Amazon Linux AMI
Operating systems & Components / Operating system

Vendor Amazon Web Services

Security Bulletin

This security bulletin contains information about 3 vulnerabilities.

1) OS Command Injection

EUVDB-ID: #VU17336

Risk: High

CVSSv4.0: 8.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/U:Amber]

CVE-ID: CVE-2019-1000018

CWE-ID: CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Exploit availability: No

Description

The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.

The vulnerability exists due to improper validation in the scp support. A remote unauthenticated attacker can perform only scp, sftp, cvs, svnserve (Subversion), rdist and/or rsync operations and execute arbitrary OS commands on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Mitigation

Update the affected packages:

i686:
    rssh-2.3.4-15.3.amzn1.i686
    rssh-debuginfo-2.3.4-15.3.amzn1.i686

src:
    rssh-2.3.4-15.3.amzn1.src

x86_64:
    rssh-debuginfo-2.3.4-15.3.amzn1.x86_64
    rssh-2.3.4-15.3.amzn1.x86_64

Vulnerable software versions

Amazon Linux AMI: All versions

CPE2.3 External links

https://alas.aws.amazon.com/ALAS-2019-1328.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.

2) OS Command Injection

EUVDB-ID: #VU17363

Risk: High

CVSSv4.0: 8.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber]

CVE-ID: CVE-2019-3463

CWE-ID: CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Exploit availability: No

Description

The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.

The vulnerability exists due to improper validation in the rsync support. A remote unauthenticated attacker can bypass the rsync support and execute arbitrary OS commands on the target system and perform only scp, sftp, cvs, svnserve (Subversion), rdist and/or rsync operations.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Mitigation

Update the affected packages:

i686:
    rssh-2.3.4-15.3.amzn1.i686
    rssh-debuginfo-2.3.4-15.3.amzn1.i686

src:
    rssh-2.3.4-15.3.amzn1.src

x86_64:
    rssh-debuginfo-2.3.4-15.3.amzn1.x86_64
    rssh-2.3.4-15.3.amzn1.x86_64

Vulnerable software versions

Amazon Linux AMI: All versions

CPE2.3 External links

https://alas.aws.amazon.com/ALAS-2019-1328.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

3) OS Command Injection

EUVDB-ID: #VU17364

Risk: High

CVSSv4.0: 8.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber]

CVE-ID: CVE-2019-3464

CWE-ID: CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Exploit availability: No

Description

The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.

The vulnerability exists due to improper validation in the rsync support. A remote unauthenticated attacker can bypass the rsync support and execute arbitrary OS commands on the target system and perform only scp, sftp, cvs, svnserve (Subversion), rdist and/or rsync operations.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Mitigation

Update the affected packages:

i686:
    rssh-2.3.4-15.3.amzn1.i686
    rssh-debuginfo-2.3.4-15.3.amzn1.i686

src:
    rssh-2.3.4-15.3.amzn1.src

x86_64:
    rssh-debuginfo-2.3.4-15.3.amzn1.x86_64
    rssh-2.3.4-15.3.amzn1.x86_64

Vulnerable software versions

Amazon Linux AMI: All versions

CPE2.3 External links

https://alas.aws.amazon.com/ALAS-2019-1328.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###