説明
rsync before 3.0.0pre6, when running a writable rsync daemon that is not using chroot, allows remote attackers to access restricted files via unknown vectors that cause rsync to create a symlink that points outside of the module's hierarchy.
AI分析AIによる分析
影響を受ける製品
slackwareslackware_linux
8.1
slackwareslackware_linux
9.0
slackwareslackware_linux
9.1
slackwareslackware_linux
10.0
slackwareslackware_linux
10.1
slackwareslackware_linux
10.2
slackwareslackware_linux
11.0
slackwareslackware_linux
12.0
rsyncrsync
2.3.1
rsyncrsync
2.3.2
rsyncrsync
2.3.2_1.2alpha
rsyncrsync
2.3.2_1.2arm
rsyncrsync
2.3.2_1.2intel
rsyncrsync
2.3.2_1.2m68k
rsyncrsync
2.3.2_1.2ppc
rsyncrsync
2.3.2_1.2sparc
rsyncrsync
2.3.2_1.3
rsyncrsync
2.4.0
rsyncrsync
2.4.1
rsyncrsync
2.4.3
rsyncrsync
2.4.4
rsyncrsync
2.4.5
rsyncrsync
2.4.6
rsyncrsync
2.4.8
rsyncrsync
2.5.0
rsyncrsync
2.5.1
rsyncrsync
2.5.2
rsyncrsync
2.5.3
rsyncrsync
2.5.4
rsyncrsync
2.5.5
rsyncrsync
2.5.6
rsyncrsync
2.5.7
rsyncrsync
2.6
rsyncrsync
2.6.1
rsyncrsync
2.6.2
rsyncrsync
2.6.5
rsyncrsync
2.6.6
rsyncrsync
2.6.7
rsyncrsync
2.6.8
rsyncrsync
2.6.9
参照
- http://lists.apple.com/archives/security-announce//2008/Jul/msg00003.html
- http://lists.opensuse.org/opensuse-security-announce/2008-01/msg00002.html
- http://rsync.samba.org/security.html#s3_0_0
- http://secunia.com/advisories/27853
- http://secunia.com/advisories/27863Vendor Advisory
- http://secunia.com/advisories/28412
- http://secunia.com/advisories/28457
- http://secunia.com/advisories/31326
- http://secunia.com/advisories/61005
- http://securitytracker.com/id?1019012
- http://support.f5.com/kb/en-us/solutions/public/15000/500/sol15549.html
- http://wiki.rpath.com/wiki/Advisories:rPSA-2007-0257
- http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:011
- http://www.securityfocus.com/archive/1/487991/100/0/threaded
- http://www.securityfocus.com/bid/26638Patch
- http://www.vupen.com/english/advisories/2007/4057
- http://www.vupen.com/english/advisories/2008/2268
- http://lists.apple.com/archives/security-announce//2008/Jul/msg00003.html
- http://lists.opensuse.org/opensuse-security-announce/2008-01/msg00002.html
- http://rsync.samba.org/security.html#s3_0_0