MidnightBSD

Advisories for scponly

CVE-2002-1469 HIGH

scponly does not properly verify the path when finding the (1) scp or (2) sftp-server programs, which could allow remote authenticated users to bypass access controls by uploading malicious programs and modifying the PATH variable in $HOME/.ssh/environment to locate those programs.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
scponly scponly 2.4
scponly scponly 2.3
CVE-2004-1162 HIGH

The unison command in scponly before 4.0 does not properly restrict programs that can be run, which could allow remote authenticated users to bypass intended access restrictions and execute arbitrary programs via the (1) -rshcmd or (2) -sshcmd flags.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
scponly scponly 3.9
scponly scponly 2.4
scponly scponly 2.0
scponly scponly 2.1
scponly scponly 2.3
scponly scponly 3.8
scponly scponly 3.5
gentoo linux *
scponly scponly 3.0
scponly scponly 3.11
CVE-2005-4532 HIGH

scponlyc in scponly 4.1 and earlier, when the operating system supports LD_PRELOAD mechanisms, allows local users to execute arbitrary code with root privileges by creating a chroot directory in their home directory, hard linking to a system setuid application, and using a modified LD_PRELOAD to modify expected function calls in the setuid application.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
scponly scponly 3.9
scponly scponly 3.3
scponly scponly 3.8
scponly scponly 3.7
scponly scponly 4.0
scponly scponly 3.1
scponly scponly 3.11
scponly scponly 3.6
scponly scponly 3.4
scponly scponly 4.1
scponly scponly 3.2
CVE-2005-4533 HIGH

Argument injection vulnerability in scponlyc in scponly 4.1 and earlier, when both scp and rsync compatibility are enabled, allows local users to execute arbitrary applications via "getopt" style argument specifications, which are not filtered.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
scponly scponly 3.9
scponly scponly 2.0
scponly scponly 2.1
scponly scponly 3.8
scponly scponly 3.5
scponly scponly 3.0
scponly scponly 3.11
scponly scponly 4.1