PT-2017-4089 · Rsync+3 · Rsync+3

Published

2017-11-03

·

Updated

2019-10-03

·

CVE-2017-17433

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions rsync versions 3.1.2 through 3.1.3-development before 2017-12-03
Description The issue is related to the recv files function in receiver.c in the rsync daemon, which allows remote attackers to bypass intended access restrictions by proceeding with certain file metadata updates before checking for a filename in the daemon filter list data structure. This can potentially impact data integrity.
Recommendations For rsync versions 3.1.2 through 3.1.3-development before 2017-12-03, consider disabling the recv files function in the daemon until a patch is available to prevent remote attackers from bypassing access restrictions. Restrict access to the daemon filter list data structure to minimize the risk of exploitation.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1219
BDU:2021-01448
CVE-2017-17433
DLA-1218-1
DSA-4068-1
MGASA-2017-0452
SUSE-SU-2018:0117-1
SUSE-SU-2018:0118-1
USN-3506-1
USN-3506-2

Affected Products

Alt Linux
Suse
Ubuntu
Rsync