rsync before 2.6.1 does not properly sanitize paths when running a read/write daemon without using chroot, which allows remote attackers to write files outside of the modules path.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Rsync | Andrew_tridgell | * | 2.6 (including) |
Red Hat Enterprise Linux 3 | RedHat | rsync-0:2.5.7-4.3E | * |