Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-9512

Опубликовано: 21 дек. 2015
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

rsync 3.1.1 allows remote attackers to write to arbitrary files via a symlink attack on a file in the synchronization path.

It was discovered that rsync did not properly perform sanity checks on certain meta-information. By sending specially crafted meta-information, a remote attacker could possibly exploit this flaw to cause an rsync endpoint to write data to files outside of the expected destination path.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5rsyncWill not fix
Red Hat Enterprise Linux 6rsyncWill not fix
Red Hat Enterprise Linux 7rsyncWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=1293854rsync: Transferring file outside destination path via just-sent symlink

EPSS

Процентиль: 92%
0.08882
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 11 лет назад

rsync 3.1.1 allows remote attackers to write to arbitrary files via a symlink attack on a file in the synchronization path.

nvd
почти 11 лет назад

rsync 3.1.1 allows remote attackers to write to arbitrary files via a symlink attack on a file in the synchronization path.

debian
почти 11 лет назад

rsync 3.1.1 allows remote attackers to write to arbitrary files via a ...

suse-cvrf
больше 9 лет назад

Security update for rsync

suse-cvrf
больше 9 лет назад

Security update for rsync

EPSS

Процентиль: 92%
0.08882
Низкий

4.3 Medium

CVSS2