PT-2007-7090 · Rsync+1 · Rsync+1

Publicado

2007-12-01

·

Atualizado

2018-10-15

·

CVE-2007-6200

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions rsync versions prior to 3.0.0pre6
Description The issue allows remote attackers to bypass exclude, exclude from, and filter rules and read or write hidden files when running a writable rsync daemon. This can be achieved via options such as symlink, partial-dir, backup-dir, and an unspecified dest option.
Recommendations For versions prior to 3.0.0pre6, update to version 3.0.0pre6 or later to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-6200
RHSA-2011:0999
RHSA-2011_0999

Produtos afetados

Red Hat
Rsync