6.4

CVE-2004-0792

Directory traversal vulnerability in the sanitize_path function in util.c for rsync 2.6.2 and earlier, when chroot is disabled, allows attackers to read or write certain files.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Andrew Tridgell ≫ Rsync Version 2.3.1
Andrew Tridgell ≫ Rsync Version 2.3.2
Andrew Tridgell ≫ Rsync Version 2.3.2_1.2 Edition alpha
Andrew Tridgell ≫ Rsync Version 2.3.2_1.2 Edition arm
Andrew Tridgell ≫ Rsync Version 2.3.2_1.2 Edition intel
Andrew Tridgell ≫ Rsync Version 2.3.2_1.2 Edition m68k
Andrew Tridgell ≫ Rsync Version 2.3.2_1.2 Edition ppc
Andrew Tridgell ≫ Rsync Version 2.3.2_1.2 Edition sparc
Andrew Tridgell ≫ Rsync Version 2.3.2_1.3
Andrew Tridgell ≫ Rsync Version 2.4.0
Andrew Tridgell ≫ Rsync Version 2.4.1
Andrew Tridgell ≫ Rsync Version 2.4.3
Andrew Tridgell ≫ Rsync Version 2.4.4
Andrew Tridgell ≫ Rsync Version 2.4.5
Andrew Tridgell ≫ Rsync Version 2.4.6
Andrew Tridgell ≫ Rsync Version 2.4.8
Andrew Tridgell ≫ Rsync Version 2.5.0
Andrew Tridgell ≫ Rsync Version 2.5.1
Andrew Tridgell ≫ Rsync Version 2.5.2
Andrew Tridgell ≫ Rsync Version 2.5.3
Andrew Tridgell ≫ Rsync Version 2.5.4
Andrew Tridgell ≫ Rsync Version 2.5.5
Andrew Tridgell ≫ Rsync Version 2.5.6
Andrew Tridgell ≫ Rsync Version 2.5.7
Andrew Tridgell ≫ Rsync Version 2.6
Andrew Tridgell ≫ Rsync Version 2.6.1
Andrew Tridgell ≫ Rsync Version 2.6.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.32% 0.812
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.4 10 4.9
AV:N/AC:L/Au:N/C:P/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://marc.info/?l=bugtraq&m=109268147522290&w=2
http://marc.info/?l=bugtraq&m=109277141223839&w=2
http://samba.org/rsync/#security_aug04
http://www.debian.org/security/2004/dsa-538
Patch
Vendor Advisory
http://www.gentoo.org/security/en/glsa/glsa-200408-17.xml
Patch
Vendor Advisory
http://www.mandriva.com/security/advisories?name=MDKSA-2004:083
http://www.novell.com/linux/security/advisories/2004_26_rsync.html
http://www.trustix.net/errata/2004/0042/
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10561