Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2007-6200

Overview

Vulnerability Score 10.0 10.0
CVE Id CVE-2007-6200
Last Modified 23 Aug 2011 10:41:35
Published 01 Dec 2007 01:46:00
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2007-6200

Summary

Unspecified vulnerability in rsync before 3.0.0pre6, when running a writable rsync daemon, allows remote attackers to bypass exclude, exclude_from, and filter and read or write hidden files via (1) symlink, (2) partial-dir, (3) backup-dir, and unspecified (4) dest options.

Vulnerable Systems

Application

  • Rsync 2.3.1

  • Rsync 2.3.2

  • Rsync 2.3.2 1.2alpha

  • Rsync 2.3.2 1.2arm

  • Rsync 2.3.2 1.2intel

  • Rsync 2.3.2 1.2m68k

  • Rsync 2.3.2 1.2ppc

  • Rsync 2.3.2 1.2sparc

  • Rsync 2.3.2 1.3

  • Rsync 2.4.0

  • Rsync 2.4.1

  • Rsync 2.4.3

  • Rsync 2.4.4

  • Rsync 2.4.5

  • Rsync 2.4.6

  • Rsync 2.4.8

  • Rsync 2.5.0

  • Rsync 2.5.1

  • Rsync 2.5.2

  • Rsync 2.5.3

  • Rsync 2.5.4

  • Rsync 2.5.5

  • Rsync 2.5.6

  • Rsync 2.5.7

  • Rsync 2.6

  • Rsync 2.6.1

  • Rsync 2.6.2

  • Rsync 2.6.5

  • Rsync 2.6.6

  • Rsync 2.6.7

  • Rsync 2.6.8

  • Rsync 2.6.9


References

SECUNIA - 27863

VUPEN - ADV-2008-2268

VUPEN - ADV-2007-4057

BID - 26639

REDHAT - RHSA-2011:0999

SECTRACK - 1019012

SECUNIA - 31326

CONFIRM - http://rsync.samba.org/security.html#s3_0_0

APPLE - APPLE-SA-2008-07-31

BUGTRAQ - 20080212 FLEA-2008-0004-1 rsync

MANDRIVA - MDVSA-2008:011

CONFIRM - http://wiki.rpath.com/wiki/Advisories:rPSA-2007-0257

SECUNIA - 28457

SECUNIA - 28412

SECUNIA - 27853

SUSE - SUSE-SR:2008:001

Related Patches

Apple 2008-07-31 Security Update 2008-005 (PPC)

Apple 2008-07-31 Security Update 2008-005 Server (PPC)

Apple 2008-07-31 Security Update 2008-005 (Leopard)

Apple 2008-07-31 Security Update 2008-005 (Intel)

Apple 2008-07-31 Security Update 2008-005 Server (Intel)

Novell SUSE 2007:4798 rsync security update for SLE 10 SP1 i586


Last Updated: 27 May 2016 10:46:24