Описание
rsync before 3.5.0 contains a symlink following vulnerability that allows local attackers to overwrite arbitrary files by placing a symlink at a predictable output path such as --log-file, --write-batch, or daemon-mode log and statistics paths. Attackers can exploit rsync's failure to reject symlinks during ancillary file writes to redirect output to arbitrary filesystem locations, achieving local privilege escalation on installations where rsync runs with elevated privileges such as setuid or privileged daemon configurations.
A symlink-following vulnerability in rsync allows local attackers to redirect predictable output paths to arbitrary filesystem locations. When rsync runs with elevated privileges (such as setuid or a privileged daemon), this enables arbitrary file overwrites and local privilege escalation.
Отчет
This Important vulnerability in rsync allows a local attacker to achieve privilege escalation by exploiting a symlink following flaw. In Red Hat environments, the risk is elevated when rsync is configured to run with elevated privileges, such as setuid or in daemon mode, enabling an attacker to overwrite arbitrary files. The requirement for local access and specific privileged configurations prevents a Critical impact.
Меры по смягчению последствий
Do not run rsync setuid or point output paths (--log-file, --write-batch, or daemon config/log files) to user-writable directories like /tmp. While fs.protected_symlinks=1 prevents simple symlink creation in sticky directories on RHEL 7+, it does not stop parent-component attacks in standard directories. If the rsyncd daemon is unneeded, disable it (systemctl disable --now rsyncd); if required, enforce least-privilege execution and restrict network access to trusted hosts.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | rsync | Affected | ||
| Red Hat Enterprise Linux 6 | rsync | Affected | ||
| Red Hat Enterprise Linux 7 | rsync | Affected | ||
| Red Hat Enterprise Linux 8 | rsync | Affected | ||
| Red Hat Enterprise Linux 9 | rsync | Affected | ||
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Affected | ||
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
7 High
CVSS3
Связанные уязвимости
rsync before 3.5.0 contains a symlink following vulnerability that allows local attackers to overwrite arbitrary files by placing a symlink at a predictable output path such as --log-file, --write-batch, or daemon-mode log and statistics paths. Attackers can exploit rsync's failure to reject symlinks during ancillary file writes to redirect output to arbitrary filesystem locations, achieving local privilege escalation on installations where rsync runs with elevated privileges such as setuid or privileged daemon configurations.
rsync before 3.5.0 contains a symlink following vulnerability that allows local attackers to overwrite arbitrary files by placing a symlink at a predictable output path such as --log-file, --write-batch, or daemon-mode log and statistics paths. Attackers can exploit rsync's failure to reject symlinks during ancillary file writes to redirect output to arbitrary filesystem locations, achieving local privilege escalation on installations where rsync runs with elevated privileges such as setuid or privileged daemon configurations.
rsync before 3.5.0 contains a symlink following vulnerability that all ...
7 High
CVSS3