PT-2017-4089 · Rsync+3 · Rsync+3
Published
2017-11-03
·
Updated
2019-10-03
·
CVE-2017-17433
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
rsync versions 3.1.2 through 3.1.3-development before 2017-12-03
Description
The issue is related to the
recv files function in receiver.c in the rsync daemon, which allows remote attackers to bypass intended access restrictions by proceeding with certain file metadata updates before checking for a filename in the daemon filter list data structure. This can potentially impact data integrity.Recommendations
For rsync versions 3.1.2 through 3.1.3-development before 2017-12-03, consider disabling the
recv files function in the daemon until a patch is available to prevent remote attackers from bypassing access restrictions. Restrict access to the daemon filter list data structure to minimize the risk of exploitation.Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Suse
Ubuntu
Rsync