Back

HIGH

When rsync is run w/o chroot, symlinks that point outside daemon's root can be created

Published Dec 1, 2007

Description

rsync before 3.0.0pre6, when running a writable rsync daemon that is not using chroot, allows remote attackers to access restricted files via unknown vectors that cause rsync to create a symlink that points outside of the module's hierarchy.

Affected products

Remediation

Red Hat statement

Red Hat does not consider this to be a security issue. Versions of rsync as shipped with Red Hat Enterprise Linux 2.1, 3, 4 and 5 behave as expected and that behavior was well documented.

Metrics

Weaknesses (1)

References (21)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 1, 2007
Updated Aug 7, 2024
Reserved Nov 30, 2007
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date Nov 28, 2007