CVE-2012-2252: Pizzashack Rssh

Medium severity, CVSS 4.4. EPSS: 0.4% chance of exploitation in the next 30 days.

Incomplete blacklist vulnerability in rssh before 2.3.4, when the rsync protocol is enabled, allows local users to bypass intended restricted shell access via the --rsh command line option.

Affected products

  • Pizzashack Rssh: up to and including 2.3.3; version 2.0.0 only; version 2.0.1 only; version 2.0.2 only; version 2.0.3 only; version 2.0.4 only; …

Published 2013-01-11. Last modified 2026-06-16.