CVE-2003-0962

8 documents7 sources
Severity
7.5HIGH
EPSS
44.3%
top 2.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 15
Latest updateMay 3

Description

Heap-based buffer overflow in rsync before 2.5.7, when running in server mode, allows remote attackers to execute arbitrary code and possibly escape the chroot jail.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages6 packages

Debianrsync< 2.5.6-1.1+3
NVDredhat/rsync5 versions+4
NVDandrew_tridgell/rsync16 versions+15
NVDengardelinux/secure_linux1.1, 1.2, 1.5+2
NVDslackware/slackware_linux4 versions+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-wp4j-j8m8-qj4m: Heap-based buffer overflow in rsync before 22022-05-03
OSV
CVE-2003-0962: Heap-based buffer overflow in rsync before 22003-12-15
CVEList
CVE-2003-0962: Heap-based buffer overflow in rsync before 22003-12-10

📋Vendor Advisories

2
Red Hat
security flaw2003-12-04
Debian
CVE-2003-0962: rsync - Heap-based buffer overflow in rsync before 2.5.7, when running in server mode, a...2003

💬Community

2
Bugzilla
CVE-2003-0962 security flaw2018-08-16
Bugzilla
CAN-2003-0962 rsync remote exploit2003-12-04