Логотип exploitDog
bind:"CVE-2017-17434"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2017-17434"

Количество 9

Количество 9

ubuntu логотип

CVE-2017-17434

около 8 лет назад

The daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, does not check for fnamecmp filenames in the daemon_filter_list data structure (in the recv_files function in receiver.c) and also does not apply the sanitize_paths protection mechanism to pathnames found in "xname follows" strings (in the read_ndx_and_attrs function in rsync.c), which allows remote attackers to bypass intended access restrictions.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2017-17434

около 8 лет назад

The daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, does not check for fnamecmp filenames in the daemon_filter_list data structure (in the recv_files function in receiver.c) and also does not apply the sanitize_paths protection mechanism to pathnames found in "xname follows" strings (in the read_ndx_and_attrs function in rsync.c), which allows remote attackers to bypass intended access restrictions.

CVSS3: 4.8
EPSS: Низкий
nvd логотип

CVE-2017-17434

около 8 лет назад

The daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, does not check for fnamecmp filenames in the daemon_filter_list data structure (in the recv_files function in receiver.c) and also does not apply the sanitize_paths protection mechanism to pathnames found in "xname follows" strings (in the read_ndx_and_attrs function in rsync.c), which allows remote attackers to bypass intended access restrictions.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2017-17434

около 8 лет назад

The daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, do ...

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-mqj4-x9gm-m5r5

больше 3 лет назад

The daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, does not check for fnamecmp filenames in the daemon_filter_list data structure (in the recv_files function in receiver.c) and also does not apply the sanitize_paths protection mechanism to pathnames found in "xname follows" strings (in the read_ndx_and_attrs function in rsync.c), which allows remote attackers to bypass intended access restrictions.

CVSS3: 9.8
EPSS: Низкий
fstec логотип

BDU:2019-04731

около 8 лет назад

Уязвимость функций recv_files и read_ndx_and_attrs демона rsync, позволяющая нарушителю обойти существующие ограничения доступа и оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 9.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2018:0118-1

около 8 лет назад

Security update for rsync

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2018:0117-1

около 8 лет назад

Security update for rsync

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2018:0101-1

около 8 лет назад

Security update for rsync

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2017-17434

The daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, does not check for fnamecmp filenames in the daemon_filter_list data structure (in the recv_files function in receiver.c) and also does not apply the sanitize_paths protection mechanism to pathnames found in "xname follows" strings (in the read_ndx_and_attrs function in rsync.c), which allows remote attackers to bypass intended access restrictions.

CVSS3: 9.8
1%
Низкий
около 8 лет назад
redhat логотип
CVE-2017-17434

The daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, does not check for fnamecmp filenames in the daemon_filter_list data structure (in the recv_files function in receiver.c) and also does not apply the sanitize_paths protection mechanism to pathnames found in "xname follows" strings (in the read_ndx_and_attrs function in rsync.c), which allows remote attackers to bypass intended access restrictions.

CVSS3: 4.8
1%
Низкий
около 8 лет назад
nvd логотип
CVE-2017-17434

The daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, does not check for fnamecmp filenames in the daemon_filter_list data structure (in the recv_files function in receiver.c) and also does not apply the sanitize_paths protection mechanism to pathnames found in "xname follows" strings (in the read_ndx_and_attrs function in rsync.c), which allows remote attackers to bypass intended access restrictions.

CVSS3: 9.8
1%
Низкий
около 8 лет назад
debian логотип
CVE-2017-17434

The daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, do ...

CVSS3: 9.8
1%
Низкий
около 8 лет назад
github логотип
GHSA-mqj4-x9gm-m5r5

The daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, does not check for fnamecmp filenames in the daemon_filter_list data structure (in the recv_files function in receiver.c) and also does not apply the sanitize_paths protection mechanism to pathnames found in "xname follows" strings (in the read_ndx_and_attrs function in rsync.c), which allows remote attackers to bypass intended access restrictions.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
fstec логотип
BDU:2019-04731

Уязвимость функций recv_files и read_ndx_and_attrs демона rsync, позволяющая нарушителю обойти существующие ограничения доступа и оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 9.8
1%
Низкий
около 8 лет назад
suse-cvrf логотип
SUSE-SU-2018:0118-1

Security update for rsync

около 8 лет назад
suse-cvrf логотип
SUSE-SU-2018:0117-1

Security update for rsync

около 8 лет назад
suse-cvrf логотип
openSUSE-SU-2018:0101-1

Security update for rsync

около 8 лет назад

Уязвимостей на страницу