6.8
CVSSv2

CVE-2007-4091

Published: 16/08/2007 Updated: 15/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple off-by-one errors in the sender.c in rsync 2.6.9 might allow remote malicious users to execute arbitrary code via directory names that are not properly handled when calling the f_name function.

Vulnerable Product Search on Vulmon Subscribe to Product

rsync rsync 2.6.9

Vendor Advisories

Debian Bug report logs - #438125 CVE-2007-4091 off-by-one in senderc Package: rsync; Maintainer for rsync is Paul Slootman <paul@debianorg>; Source for rsync is src:rsync (PTS, buildd, popcon) Reported by: Nico Golde <nion@debianorg> Date: Wed, 15 Aug 2007 14:24:01 UTC Severity: serious Tags: security Found in v ...
Sebastian Krahmer discovered that rsync contained an off-by-one miscalculation when handling certain file paths By creating a specially crafted tree of files and tricking an rsync server into processing them, a remote attacker could write a single NULL to stack memory, possibly leading to arbitrary code execution ...
Sebastian Krahmer discovered that rsync, a fast remote file copy program, contains an off-by-one error which might allow remote attackers to execute arbitrary code via long directory names For the old stable distribution (sarge), this problem is not present For the stable distribution (etch), this problem has been fixed in version 269-2etch1 F ...