FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2004-0792

This CVE name corresponds to:

Entered Topic
2004-08-26 rsync -- path sanitizing vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2004-0792
Phase Assigned(20040817)

Description

Directory traversal vulnerability in the sanitize_path function in util.c for rsync 2.6.2 and earlier, when chroot is disabled, allows attackers to read or write certain files.

References

Source Reference
CONFIRM http://samba.org/rsync/#security_aug04
DEBIAN DSA-538
GENTOO GLSA-200408-17
MANDRAKE MDKSA-2004:083
SUSE SUSE-SA:2004:026
TRUSTIX 2004-0042
BUGTRAQ 20040816 TSSA-2004-020-ES - rsync
BUGTRAQ 20040817 LNSA-#2004-0017: rsync (Aug, 17 2004)
OVAL oval:org.mitre.oval:def:10561