Pizzashack maintains a narrowly focused remote-shell access product, RSSH, whose vulnerability profile skews strongly toward critical-severity outcomes despite a small disclosure volume. The recurring weaknesses—improper initialization, input validation failures, and command-injection flaws—reflect the command-parsing and shell-interaction demands inherent to a remote-access utility and represent high-risk attack vectors in environments where RSSH is deployed. Defenders should prioritize patches for this product given its severity tendency; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pizzashack over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-3464CRITICAL Insufficient sanitization of environment variables passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restrict users to perform only rsync | Feb 6, 2019 | 9.8 | 32 | NO | NO |
CVE-2019-3463CRITICAL Insufficient sanitization of arguments passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restrict users to perform only rsync operations, | Feb 6, 2019 | 9.8 | 32 | NO | NO |
CVE-2019-1000018HIGH rssh version 2.3.4 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in allowscp permission that can result in Lo | Feb 4, 2019 | 7.8 | 26 | NO | NO |
CVE-2004-1628HIGH Format string vulnerability in log.c in rssh before 2.2.2 allows remote authenticated users to execute arbitrary code. | Oct 23, 2004 | 9.0 | 26 | NO | NO |
CVE-2012-2252MEDIUM Incomplete blacklist vulnerability in rssh before 2.3.4, when the rsync protocol is enabled, allows local users to bypass intended restricted shell access via the --rsh command lin | Jan 11, 2013 | 4.4 | 17 | NO | NO |
CVE-2012-2251MEDIUM rssh 2.3.2, as used by Debian, Fedora, and others, when the rsync protocol is enabled, allows local users to bypass intended restricted shell access via a (1) "-e" or (2) "--" comm | Jan 11, 2013 | 4.4 | 17 | NO | NO |
rssh 2.3.3 and earlier allows local users to bypass intended restricted shell access via crafted environment variables in the command line. | Aug 31, 2012 | 2.1 | 15 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pizzashack.
Media articles that mention a CVE ID that affects a product developed by Pizzashack — matched by CVE ID, not by vendor name.