PT-2004-1564 · Rsync · Rsync
Published
2004-04-30
·
Updated
2017-10-11
·
CVE-2004-0426
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
rsync versions prior to 2.6.1
Description
The issue arises from improper path sanitization when running a read/write daemon without using chroot. This allows remote attackers to write files outside of the module's path.
Recommendations
For versions prior to 2.6.1, update to version 2.6.1 or later to resolve the issue. As a temporary workaround, consider using chroot to restrict the daemon's access to the module's path.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rsync