5
CVSSv2

CVE-2004-0426

Published: 07/07/2004 Updated: 11/10/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

rsync prior to 2.6.1 does not properly sanitize paths when running a read/write daemon without using chroot, which allows remote malicious users to write files outside of the module's path.

Vulnerable Product Search on Vulmon Subscribe to Product

andrew tridgell rsync

Vendor Advisories

Synopsis rsync security update Type/Severity Security Advisory: Important Topic An updated rsync package that fixes a directory traversal security flaw isnow available Description Rsync is a program for synchronizing files over a networkRsync before 261 does not properly sanitize paths ...
A vulnerability was discovered in rsync, a file transfer program, whereby a remote user could cause an rsync daemon to write files outside of the intended directory tree This vulnerability is not exploitable when the daemon is configured with the 'chroot' option For the current stable distribution (woody) this problem has been fixed in version 2 ...