CVE Vulnerabilities

CVE-2004-0792

Published: Oct 20, 2004 | Modified: Oct 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Directory traversal vulnerability in the sanitize_path function in util.c for rsync 2.6.2 and earlier, when chroot is disabled, allows attackers to read or write certain files.

Affected Software

Name Vendor Start Version End Version
Rsync Andrew_tridgell 2.3.1 (including) 2.3.1 (including)
Rsync Andrew_tridgell 2.3.2 (including) 2.3.2 (including)
Rsync Andrew_tridgell 2.3.2_1.2 (including) 2.3.2_1.2 (including)
Rsync Andrew_tridgell 2.3.2_1.3 (including) 2.3.2_1.3 (including)
Rsync Andrew_tridgell 2.4.0 (including) 2.4.0 (including)
Rsync Andrew_tridgell 2.4.1 (including) 2.4.1 (including)
Rsync Andrew_tridgell 2.4.3 (including) 2.4.3 (including)
Rsync Andrew_tridgell 2.4.4 (including) 2.4.4 (including)
Rsync Andrew_tridgell 2.4.5 (including) 2.4.5 (including)
Rsync Andrew_tridgell 2.4.6 (including) 2.4.6 (including)
Rsync Andrew_tridgell 2.4.8 (including) 2.4.8 (including)
Rsync Andrew_tridgell 2.5.0 (including) 2.5.0 (including)
Rsync Andrew_tridgell 2.5.1 (including) 2.5.1 (including)
Rsync Andrew_tridgell 2.5.2 (including) 2.5.2 (including)
Rsync Andrew_tridgell 2.5.3 (including) 2.5.3 (including)
Rsync Andrew_tridgell 2.5.4 (including) 2.5.4 (including)
Rsync Andrew_tridgell 2.5.5 (including) 2.5.5 (including)
Rsync Andrew_tridgell 2.5.6 (including) 2.5.6 (including)
Rsync Andrew_tridgell 2.5.7 (including) 2.5.7 (including)
Rsync Andrew_tridgell 2.6 (including) 2.6 (including)
Rsync Andrew_tridgell 2.6.1 (including) 2.6.1 (including)
Rsync Andrew_tridgell 2.6.2 (including) 2.6.2 (including)
Red Hat Enterprise Linux 3 RedHat rsync-0:2.5.7-5.3E *
Rsync Ubuntu dapper *
Rsync Ubuntu devel *
Rsync Ubuntu edgy *
Rsync Ubuntu feisty *

References