CVE-2007-6199
published 2007-12-01CVE-2007-6199: rsync before 3.0.0pre6, when running a writable rsync daemon that is not using chroot, allows remote attackers to access restricted files via unknown vectors…
PriorityP342critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
4.14%
89.8th percentile
rsync before 3.0.0pre6, when running a writable rsync daemon that is not using chroot, allows remote attackers to access restricted files via unknown vectors that cause rsync to create a symlink that points outside of the module's hierarchy.
Affected
37 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | rsync | < rsync 2.6.9-6 (bookworm) | rsync 2.6.9-6 (bookworm) |
| rsync | rsync | — | — |
| rsync | rsync | — | — |
| rsync | rsync | — | — |
| rsync | rsync | — | — |
| rsync | rsync | — | — |
| rsync | rsync | — | — |
| rsync | rsync | — | — |
| rsync | rsync | — | — |
| rsync | rsync | — | — |
| rsync | rsync | — | — |
| rsync | rsync | — | — |
| rsync | rsync | — | — |
| rsync | rsync | — | — |
| rsync | rsync | — | — |
| rsync | rsync | — | — |
| rsync | rsync | — | — |
| rsync | rsync | — | — |
| rsync | rsync | — | — |
| rsync | rsync | — | — |
| rsync | rsync | — | — |
| rsync | rsync | — | — |
| rsync | rsync | — | — |
| rsync | rsync | — | — |
| rsync | rsync | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3LOW
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r5c5-5849-8rr9: rsync before 3
ghsa_unreviewed·2022-05-01
CVE-2007-6199 [HIGH] GHSA-r5c5-5849-8rr9: rsync before 3
rsync before 3.0.0pre6, when running a writable rsync daemon that is not using chroot, allows remote attackers to access restricted files via unknown vectors that cause rsync to create a symlink that points outside of the module's hierarchy.
OSV
CVE-2007-6199: rsync before 3
osv·2007-12-01·CVSS 9.3
CVE-2007-6199 [CRITICAL] CVE-2007-6199: rsync before 3
rsync before 3.0.0pre6, when running a writable rsync daemon that is not using chroot, allows remote attackers to access restricted files via unknown vectors that cause rsync to create a symlink that points outside of the module's hierarchy.
Red Hat
When rsync is run w/o chroot, symlinks that point outside daemon's root can be created
vendor_redhat·2007-11-28·CVSS 9.3
CVE-2007-6199 [CRITICAL] When rsync is run w/o chroot, symlinks that point outside daemon's root can be created
When rsync is run w/o chroot, symlinks that point outside daemon's root can be created
rsync before 3.0.0pre6, when running a writable rsync daemon that is not using chroot, allows remote attackers to access restricted files via unknown vectors that cause rsync to create a symlink that points outside of the module's hierarchy.
Statement: Red Hat does not consider this to be a security issue. Versions of rsync as shipped with Red Hat Enterprise Linux 2.1, 3, 4 and 5 behave as expected and that behavior was well documented.
Debian
CVE-2007-6199: rsync - rsync before 3.0.0pre6, when running a writable rsync daemon that is not using c...
vendor_debian·2007·CVSS 9.3
CVE-2007-6199 [CRITICAL] CVE-2007-6199: rsync - rsync before 3.0.0pre6, when running a writable rsync daemon that is not using c...
rsync before 3.0.0pre6, when running a writable rsync daemon that is not using chroot, allows remote attackers to access restricted files via unknown vectors that cause rsync to create a symlink that points outside of the module's hierarchy.
Scope: local
bookworm: resolved (fixed in 2.6.9-6)
bullseye: resolved (fixed in 2.6.9-6)
forky: resolved (fixed in 2.6.9-6)
sid: resolved (fixed in 2.6.9-6)
trixie: resolved (fixed in 2.6.9-6)
No detection rules found.
No public exploits indexed.
http://lists.apple.com/archives/security-announce//2008/Jul/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-01/msg00002.htmlhttp://rsync.samba.org/security.html#s3_0_0http://secunia.com/advisories/27853http://secunia.com/advisories/27863http://secunia.com/advisories/28412http://secunia.com/advisories/28457http://secunia.com/advisories/31326http://secunia.com/advisories/61005http://securitytracker.com/id?1019012http://support.f5.com/kb/en-us/solutions/public/15000/500/sol15549.htmlhttp://wiki.rpath.com/wiki/Advisories:rPSA-2007-0257http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:011http://www.securityfocus.com/archive/1/487991/100/0/threadedhttp://www.securityfocus.com/bid/26638http://www.vupen.com/english/advisories/2007/4057http://www.vupen.com/english/advisories/2008/2268http://lists.apple.com/archives/security-announce//2008/Jul/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-01/msg00002.htmlhttp://rsync.samba.org/security.html#s3_0_0http://secunia.com/advisories/27853http://secunia.com/advisories/27863http://secunia.com/advisories/28412http://secunia.com/advisories/28457http://secunia.com/advisories/31326http://secunia.com/advisories/61005http://securitytracker.com/id?1019012http://support.f5.com/kb/en-us/solutions/public/15000/500/sol15549.htmlhttp://wiki.rpath.com/wiki/Advisories:rPSA-2007-0257http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:011http://www.securityfocus.com/archive/1/487991/100/0/threadedhttp://www.securityfocus.com/bid/26638http://www.vupen.com/english/advisories/2007/4057http://www.vupen.com/english/advisories/2008/2268
2007-12-01
Published