Computer Security
[EN] securityvulns.ru no-pyccku


rsync security restrictions bypass
Published:05.12.2007
Source:
SecurityVulns ID:8404
Type:remote
Threat Level:
5/10
Affected:RSYNC : rsync 3.0
CVE:CVE-2007-6200 (Unspecified vulnerability in rsync before 3.0.0pre6, when running a writable rsync daemon, allows remote attackers to bypass exclude, exclude_from, and filter and read or write hidden files via (1) symlink, (2) partial-dir, (3) backup-dir, and unspecified (4) dest options.)
 CVE-2007-6199 (rsync before 3.0.0pre6, when running a writable rsync daemon that is not using chroot, allows remote attackers to access restricted files via unknown vectors that cause rsync to create a symlink that points outside of the module's hierarchy.)
Original documentdocumentRPATH, rPSA-2007-0257-1 rsync (05.12.2007)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod