OpenBSD VuXML: Documenting security issues in the OpenBSD Ports & Packages Collection

rsync -- path-sanitizing bug that affects daemon mode if chroot is disabled

Affected packages
rsync < 2.6.2p1

Details

VuXML ID 8f635e70-ee5c-11d8-8e25-00304f19272c
Discovery 2004-08-12
Entry 2004-08-14

There is a path-sanitizing bug that affects daemon, but only if chroot is disabled. It does NOT affect the normal send/receive filenames that specify what files should be transferred (this is because these names happen to get sanitized twice, and thus the second call removes any lingering leading slash(es) that the first call left behind). It does affect certain option paths that cause auxilliary files to be read or written.

References

URL http://samba.org/rsync/#security_aug04