Back

MEDIUM

rsync off by one flaw

Published Aug 16, 2007

Description

Multiple off-by-one errors in the sender.c in rsync 2.6.9 might allow remote attackers to execute arbitrary code via directory names that are not properly handled when calling the f_name function.

Affected products

Remediation

Red Hat statement

Not vulnerable. This flaw did not affect Red Hat Enterprise Linux 2.1, 3, or 4 due to the version of rsync. This flaw does exist in Red Hat Enterprise Linux 5, but due to the nature of the flaw it is not exploitable with any security consequence due to stack-protector.

Metrics

Weaknesses (1)

References (28)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 16, 2007
Updated Aug 7, 2024
Reserved Jul 30, 2007
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Aug 15, 2007