CVE-2007-4091
published 2007-08-16CVE-2007-4091: Multiple off-by-one errors in the sender.c in rsync 2.6.9 might allow remote attackers to execute arbitrary code via directory names that are not properly…
PriorityP335medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
3.35%
87.4th percentile
Multiple off-by-one errors in the sender.c in rsync 2.6.9 might allow remote attackers to execute arbitrary code via directory names that are not properly handled when calling the f_name function.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | rsync | < rsync 2.6.9-5 (bookworm) | rsync 2.6.9-5 (bookworm) |
| rsync | rsync | — | — |
| samba | rsync | >= 0 < 2.6.9-5 | 2.6.9-5 |
| samba | rsync | >= 0 < 2.6.9-5 | 2.6.9-5 |
| samba | rsync | >= 0 < 2.6.9-5 | 2.6.9-5 |
| samba | rsync | >= 0 < 2.6.9-5 | 2.6.9-5 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f26v-rp94-xv52: Multiple off-by-one errors in the sender
ghsa_unreviewed·2022-05-01
CVE-2007-4091 [MEDIUM] GHSA-f26v-rp94-xv52: Multiple off-by-one errors in the sender
Multiple off-by-one errors in the sender.c in rsync 2.6.9 might allow remote attackers to execute arbitrary code via directory names that are not properly handled when calling the f_name function.
OSV
CVE-2007-4091: Multiple off-by-one errors in the sender
osv·2007-08-16·CVSS 6.8
CVE-2007-4091 [MEDIUM] CVE-2007-4091: Multiple off-by-one errors in the sender
Multiple off-by-one errors in the sender.c in rsync 2.6.9 might allow remote attackers to execute arbitrary code via directory names that are not properly handled when calling the f_name function.
Ubuntu
rsync vulnerability
vendor_ubuntu·2007-08-20
CVE-2007-4091 rsync vulnerability
Title: rsync vulnerability
Summary: rsync vulnerability
Sebastian Krahmer discovered that rsync contained an off-by-one
miscalculation when handling certain file paths. By creating a specially
crafted tree of files and tricking an rsync server into processing them,
a remote attacker could write a single NULL to stack memory, possibly
leading to arbitrary code execution.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
rsync off by one flaw
vendor_redhat·2007-08-15·CVSS 6.8
CVE-2007-4091 [MEDIUM] CWE-193 rsync off by one flaw
rsync off by one flaw
Multiple off-by-one errors in the sender.c in rsync 2.6.9 might allow remote attackers to execute arbitrary code via directory names that are not properly handled when calling the f_name function.
Statement: Not vulnerable. This flaw did not affect Red Hat Enterprise Linux 2.1, 3, or 4 due to the version of rsync.
This flaw does exist in Red Hat Enterprise Linux 5, but due to the nature of the flaw it is not exploitable with any security consequence due to stack-protector.
Debian
CVE-2007-4091: rsync - Multiple off-by-one errors in the sender.c in rsync 2.6.9 might allow remote att...
vendor_debian·2007·CVSS 6.8
CVE-2007-4091 [MEDIUM] CVE-2007-4091: rsync - Multiple off-by-one errors in the sender.c in rsync 2.6.9 might allow remote att...
Multiple off-by-one errors in the sender.c in rsync 2.6.9 might allow remote attackers to execute arbitrary code via directory names that are not properly handled when calling the f_name function.
Scope: local
bookworm: resolved (fixed in 2.6.9-5)
bullseye: resolved (fixed in 2.6.9-5)
forky: resolved (fixed in 2.6.9-5)
sid: resolved (fixed in 2.6.9-5)
trixie: resolved (fixed in 2.6.9-5)
No detection rules found.
No public exploits indexed.
http://article.gmane.org/gmane.linux.debian.devel.bugs.general/291908http://c-skills.blogspot.com/2007/08/cve-2007-4091.htmlhttp://secunia.com/advisories/26493http://secunia.com/advisories/26518http://secunia.com/advisories/26537http://secunia.com/advisories/26543http://secunia.com/advisories/26548http://secunia.com/advisories/26634http://secunia.com/advisories/26822http://secunia.com/advisories/26911http://secunia.com/advisories/27896http://secunia.com/advisories/61039http://security.gentoo.org/glsa/glsa-200709-13.xmlhttp://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.481089http://support.f5.com/kb/en-us/solutions/public/15000/500/sol15548.htmlhttp://www.debian.org/security/2007/dsa-1360http://www.novell.com/linux/security/advisories/2007_17_sr.htmlhttp://www.securityfocus.com/archive/1/477628/100/0/threadedhttp://www.securityfocus.com/bid/25336http://www.trustix.org/errata/2007/0026/http://www.ubuntu.com/usn/usn-500-1http://www.vupen.com/english/advisories/2007/2915https://exchange.xforce.ibmcloud.com/vulnerabilities/36072https://issues.rpath.com/browse/RPL-1647http://article.gmane.org/gmane.linux.debian.devel.bugs.general/291908http://c-skills.blogspot.com/2007/08/cve-2007-4091.htmlhttp://secunia.com/advisories/26493http://secunia.com/advisories/26518http://secunia.com/advisories/26537http://secunia.com/advisories/26543http://secunia.com/advisories/26548http://secunia.com/advisories/26634http://secunia.com/advisories/26822http://secunia.com/advisories/26911http://secunia.com/advisories/27896http://secunia.com/advisories/61039http://security.gentoo.org/glsa/glsa-200709-13.xmlhttp://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.481089http://support.f5.com/kb/en-us/solutions/public/15000/500/sol15548.htmlhttp://www.debian.org/security/2007/dsa-1360http://www.novell.com/linux/security/advisories/2007_17_sr.htmlhttp://www.securityfocus.com/archive/1/477628/100/0/threadedhttp://www.securityfocus.com/bid/25336http://www.trustix.org/errata/2007/0026/http://www.ubuntu.com/usn/usn-500-1http://www.vupen.com/english/advisories/2007/2915https://exchange.xforce.ibmcloud.com/vulnerabilities/36072https://issues.rpath.com/browse/RPL-1647
2007-08-16
Published