Oval Definition:oval:com.redhat.rhsa:def:20040436
Revision Date:2004-09-01Version:502
Title:RHSA-2004:436: rsync security update (Moderate)
Description:The rsync program synchronizes files over a network. Versions of rsync up to and including version 2.6.2 contain a path sanitization issue. This issue could allow an attacker to read or write files outside of the rsync directory. This vulnerability is only exploitable when an rsync server is enabled and is not running within a chroot. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0792 to this issue.

Users of rsync are advised to upgrade to this updated package, which contains a backported patch and is not affected by this issue.
Family:unixClass:patch
Status:Reference(s):CVE-2004-0792
RHSA-2004:436-01
Platform(s):Red Hat Enterprise Linux 3
Product(s):
Definition Synopsis
  • Red Hat Enterprise Linux 3 is installed
  • AND rsync is earlier than 0:2.5.7-5.3E
  • AND rsync is signed with Red Hat master key
  • BACK