cbcvebase.
CVE-2007-4091
published 2007-08-16

CVE-2007-4091: Multiple off-by-one errors in the sender.c in rsync 2.6.9 might allow remote attackers to execute arbitrary code via directory names that are not properly…

PriorityP335medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
3.35%
87.4th percentile
Multiple off-by-one errors in the sender.c in rsync 2.6.9 might allow remote attackers to execute arbitrary code via directory names that are not properly handled when calling the f_name function.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianrsync< rsync 2.6.9-5 (bookworm)rsync 2.6.9-5 (bookworm)
rsyncrsync
sambarsync>= 0 < 2.6.9-52.6.9-5
sambarsync>= 0 < 2.6.9-52.6.9-5
sambarsync>= 0 < 2.6.9-52.6.9-5
sambarsync>= 0 < 2.6.9-52.6.9-5

CVSS provenance

nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.