PT-2007-7090 · Rsync+1 · Rsync+1

Published

2007-12-01

·

Updated

2018-10-15

·

CVE-2007-6200

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions rsync versions prior to 3.0.0pre6
Description The issue allows remote attackers to bypass exclude, exclude from, and filter rules and read or write hidden files when running a writable rsync daemon. This can be achieved via options such as symlink, partial-dir, backup-dir, and an unspecified dest option.
Recommendations For versions prior to 3.0.0pre6, update to version 3.0.0pre6 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-6200
RHSA-2011:0999
RHSA-2011_0999

Affected Products

Red Hat
Rsync