cbcvebase.
CVE-2007-6199
published 2007-12-01

CVE-2007-6199: rsync before 3.0.0pre6, when running a writable rsync daemon that is not using chroot, allows remote attackers to access restricted files via unknown vectors…

PriorityP342critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
4.14%
89.8th percentile
rsync before 3.0.0pre6, when running a writable rsync daemon that is not using chroot, allows remote attackers to access restricted files via unknown vectors that cause rsync to create a symlink that points outside of the module's hierarchy.

Affected

37 ranges· showing 25
VendorProductVersion rangeFixed in
debianrsync< rsync 2.6.9-6 (bookworm)rsync 2.6.9-6 (bookworm)
rsyncrsync
rsyncrsync
rsyncrsync
rsyncrsync
rsyncrsync
rsyncrsync
rsyncrsync
rsyncrsync
rsyncrsync
rsyncrsync
rsyncrsync
rsyncrsync
rsyncrsync
rsyncrsync
rsyncrsync
rsyncrsync
rsyncrsync
rsyncrsync
rsyncrsync
rsyncrsync
rsyncrsync
rsyncrsync
rsyncrsync
rsyncrsync

CVSS provenance

nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3LOW
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.