CVE-2004-0792

Directory traversal vulnerability in the sanitize_path function in util.c for rsync 2.6.2 and earlier, when chroot is disabled, allows attackers to read or write certain files.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:andrew_tridgell:rsync:2.3.1:*:*:*:*:*:*:*
cpe:2.3:a:andrew_tridgell:rsync:2.3.2:*:*:*:*:*:*:*
cpe:2.3:a:andrew_tridgell:rsync:2.3.2_1.2:*:alpha:*:*:*:*:*
cpe:2.3:a:andrew_tridgell:rsync:2.3.2_1.2:*:arm:*:*:*:*:*
cpe:2.3:a:andrew_tridgell:rsync:2.3.2_1.2:*:intel:*:*:*:*:*
cpe:2.3:a:andrew_tridgell:rsync:2.3.2_1.2:*:m68k:*:*:*:*:*
cpe:2.3:a:andrew_tridgell:rsync:2.3.2_1.2:*:ppc:*:*:*:*:*
cpe:2.3:a:andrew_tridgell:rsync:2.3.2_1.2:*:sparc:*:*:*:*:*
cpe:2.3:a:andrew_tridgell:rsync:2.3.2_1.3:*:*:*:*:*:*:*
cpe:2.3:a:andrew_tridgell:rsync:2.4.0:*:*:*:*:*:*:*
cpe:2.3:a:andrew_tridgell:rsync:2.4.1:*:*:*:*:*:*:*
cpe:2.3:a:andrew_tridgell:rsync:2.4.3:*:*:*:*:*:*:*
cpe:2.3:a:andrew_tridgell:rsync:2.4.4:*:*:*:*:*:*:*
cpe:2.3:a:andrew_tridgell:rsync:2.4.5:*:*:*:*:*:*:*
cpe:2.3:a:andrew_tridgell:rsync:2.4.6:*:*:*:*:*:*:*
cpe:2.3:a:andrew_tridgell:rsync:2.4.8:*:*:*:*:*:*:*
cpe:2.3:a:andrew_tridgell:rsync:2.5.0:*:*:*:*:*:*:*
cpe:2.3:a:andrew_tridgell:rsync:2.5.1:*:*:*:*:*:*:*
cpe:2.3:a:andrew_tridgell:rsync:2.5.2:*:*:*:*:*:*:*
cpe:2.3:a:andrew_tridgell:rsync:2.5.3:*:*:*:*:*:*:*
cpe:2.3:a:andrew_tridgell:rsync:2.5.4:*:*:*:*:*:*:*
cpe:2.3:a:andrew_tridgell:rsync:2.5.5:*:*:*:*:*:*:*
cpe:2.3:a:andrew_tridgell:rsync:2.5.6:*:*:*:*:*:*:*
cpe:2.3:a:andrew_tridgell:rsync:2.5.7:*:*:*:*:*:*:*
cpe:2.3:a:andrew_tridgell:rsync:2.6:*:*:*:*:*:*:*
cpe:2.3:a:andrew_tridgell:rsync:2.6.1:*:*:*:*:*:*:*
cpe:2.3:a:andrew_tridgell:rsync:2.6.2:*:*:*:*:*:*:*

History

20 Nov 2024, 23:49

Type Values Removed Values Added
References () http://marc.info/?l=bugtraq&m=109268147522290&w=2 - () http://marc.info/?l=bugtraq&m=109268147522290&w=2 -
References () http://marc.info/?l=bugtraq&m=109277141223839&w=2 - () http://marc.info/?l=bugtraq&m=109277141223839&w=2 -
References () http://samba.org/rsync/#security_aug04 - () http://samba.org/rsync/#security_aug04 -
References () http://www.debian.org/security/2004/dsa-538 - Patch, Vendor Advisory () http://www.debian.org/security/2004/dsa-538 - Patch, Vendor Advisory
References () http://www.gentoo.org/security/en/glsa/glsa-200408-17.xml - Patch, Vendor Advisory () http://www.gentoo.org/security/en/glsa/glsa-200408-17.xml - Patch, Vendor Advisory
References () http://www.mandriva.com/security/advisories?name=MDKSA-2004:083 - () http://www.mandriva.com/security/advisories?name=MDKSA-2004:083 -
References () http://www.novell.com/linux/security/advisories/2004_26_rsync.html - () http://www.novell.com/linux/security/advisories/2004_26_rsync.html -
References () http://www.trustix.net/errata/2004/0042/ - () http://www.trustix.net/errata/2004/0042/ -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10561 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10561 -

Information

Published : 2004-10-20 04:00

Updated : 2024-11-20 23:49


NVD link : CVE-2004-0792

Mitre link : CVE-2004-0792

CVE.ORG link : CVE-2004-0792


JSON object : View

Products Affected

andrew_tridgell

  • rsync