PT-2004-1564 · Rsync · Rsync
Publicado
2004-04-30
·
Atualizado
2017-10-11
·
CVE-2004-0426
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
rsync versions prior to 2.6.1
Description
The issue arises from improper path sanitization when running a read/write daemon without using chroot. This allows remote attackers to write files outside of the module's path.
Recommendations
For versions prior to 2.6.1, update to version 2.6.1 or later to resolve the issue. As a temporary workaround, consider using chroot to restrict the daemon's access to the module's path.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Rsync