Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2007-6199

Overview

Vulnerability Score 9.3 9.3
CVE Id CVE-2007-6199
Last Modified 07 Mar 2011 10:02:08
Published 01 Dec 2007 01:46:00
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2007-6199

Summary

rsync before 3.0.0pre6, when running a writable rsync daemon that is not using chroot, allows remote attackers to access restricted files via unknown vectors that cause rsync to create a symlink that points outside of the module's hierarchy.

Vulnerable Systems

Application

  • Rsync 2.3.1

  • Rsync 2.3.2

  • Rsync 2.3.2 1.2alpha

  • Rsync 2.3.2 1.2arm

  • Rsync 2.3.2 1.2intel

  • Rsync 2.3.2 1.2m68k

  • Rsync 2.3.2 1.2ppc

  • Rsync 2.3.2 1.2sparc

  • Rsync 2.3.2 1.3

  • Rsync 2.4.0

  • Rsync 2.4.1

  • Rsync 2.4.3

  • Rsync 2.4.4

  • Rsync 2.4.5

  • Rsync 2.4.6

  • Rsync 2.4.8

  • Rsync 2.5.0

  • Rsync 2.5.1

  • Rsync 2.5.2

  • Rsync 2.5.3

  • Rsync 2.5.4

  • Rsync 2.5.5

  • Rsync 2.5.6

  • Rsync 2.5.7

  • Rsync 2.6

  • Rsync 2.6.1

  • Rsync 2.6.2

  • Rsync 2.6.5

  • Rsync 2.6.6

  • Rsync 2.6.7

  • Rsync 2.6.8

  • Rsync 2.6.9


References

BID - 26638

VUPEN - ADV-2008-2268

VUPEN - ADV-2007-4057

SECTRACK - 1019012

SECUNIA - 31326

SECUNIA - 27863

CONFIRM - http://rsync.samba.org/security.html#s3_0_0

APPLE - APPLE-SA-2008-07-31

BUGTRAQ - 20080212 FLEA-2008-0004-1 rsync

MANDRIVA - MDVSA-2008:011

CONFIRM - http://wiki.rpath.com/wiki/Advisories:rPSA-2007-0257

SECUNIA - 28457

SECUNIA - 28412

SECUNIA - 27853

SUSE - SUSE-SR:2008:001

Related Patches

Apple 2008-07-31 Security Update 2008-005 (PPC)

Apple 2008-07-31 Security Update 2008-005 Server (PPC)

Apple 2008-07-31 Security Update 2008-005 (Leopard)

Apple 2008-07-31 Security Update 2008-005 (Intel)

Apple 2008-07-31 Security Update 2008-005 Server (Intel)

Novell SUSE 2007:4798 rsync security update for SLE 10 SP1 i586


Last Updated: 27 May 2016 10:46:24