CVE-2007-6200
published 2007-12-01CVE-2007-6200: Unspecified vulnerability in rsync before 3.0.0pre6, when running a writable rsync daemon, allows remote attackers to bypass exclude, exclude_from, and filter…
PriorityP343critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
5.44%
91.8th percentile
Unspecified vulnerability in rsync before 3.0.0pre6, when running a writable rsync daemon, allows remote attackers to bypass exclude, exclude_from, and filter and read or write hidden files via (1) symlink, (2) partial-dir, (3) backup-dir, and unspecified (4) dest options.
Affected
37 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | rsync | < rsync 2.6.9-6 (bookworm) | rsync 2.6.9-6 (bookworm) |
| rsync | rsync | — | — |
| rsync | rsync | — | — |
| rsync | rsync | — | — |
| rsync | rsync | — | — |
| rsync | rsync | — | — |
| rsync | rsync | — | — |
| rsync | rsync | — | — |
| rsync | rsync | — | — |
| rsync | rsync | — | — |
| rsync | rsync | — | — |
| rsync | rsync | — | — |
| rsync | rsync | — | — |
| rsync | rsync | — | — |
| rsync | rsync | — | — |
| rsync | rsync | — | — |
| rsync | rsync | — | — |
| rsync | rsync | — | — |
| rsync | rsync | — | — |
| rsync | rsync | — | — |
| rsync | rsync | — | — |
| rsync | rsync | — | — |
| rsync | rsync | — | — |
| rsync | rsync | — | — |
| rsync | rsync | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0LOW
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
rsync excluded content access restrictions bypass via symlinks
vendor_redhat·2007-11-28·CVSS 10.0
CVE-2007-6200 [CRITICAL] rsync excluded content access restrictions bypass via symlinks
rsync excluded content access restrictions bypass via symlinks
Unspecified vulnerability in rsync before 3.0.0pre6, when running a writable rsync daemon, allows remote attackers to bypass exclude, exclude_from, and filter and read or write hidden files via (1) symlink, (2) partial-dir, (3) backup-dir, and unspecified (4) dest options.
Package: rsync (Red Hat Enterprise Linux 4) - Will not fix
Debian
CVE-2007-6200: rsync - Unspecified vulnerability in rsync before 3.0.0pre6, when running a writable rsy...
vendor_debian·2007·CVSS 10.0
CVE-2007-6200 [CRITICAL] CVE-2007-6200: rsync - Unspecified vulnerability in rsync before 3.0.0pre6, when running a writable rsy...
Unspecified vulnerability in rsync before 3.0.0pre6, when running a writable rsync daemon, allows remote attackers to bypass exclude, exclude_from, and filter and read or write hidden files via (1) symlink, (2) partial-dir, (3) backup-dir, and unspecified (4) dest options.
Scope: local
bookworm: resolved (fixed in 2.6.9-6)
bullseye: resolved (fixed in 2.6.9-6)
forky: resolved (fixed in 2.6.9-6)
sid: resolved (fixed in 2.6.9-6)
trixie: resolved (fixed in 2.6.9-6)
GHSA
GHSA-2w9v-97wx-v5mj: Unspecified vulnerability in rsync before 3
ghsa_unreviewed·2022-05-01
CVE-2007-6200 [HIGH] GHSA-2w9v-97wx-v5mj: Unspecified vulnerability in rsync before 3
Unspecified vulnerability in rsync before 3.0.0pre6, when running a writable rsync daemon, allows remote attackers to bypass exclude, exclude_from, and filter and read or write hidden files via (1) symlink, (2) partial-dir, (3) backup-dir, and unspecified (4) dest options.
OSV
CVE-2007-6200: Unspecified vulnerability in rsync before 3
osv·2007-12-01·CVSS 10.0
CVE-2007-6200 [CRITICAL] CVE-2007-6200: Unspecified vulnerability in rsync before 3
Unspecified vulnerability in rsync before 3.0.0pre6, when running a writable rsync daemon, allows remote attackers to bypass exclude, exclude_from, and filter and read or write hidden files via (1) symlink, (2) partial-dir, (3) backup-dir, and unspecified (4) dest options.
No detection rules found.
No public exploits indexed.
http://lists.apple.com/archives/security-announce//2008/Jul/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-01/msg00002.htmlhttp://rsync.samba.org/security.html#s3_0_0http://secunia.com/advisories/27853http://secunia.com/advisories/27863http://secunia.com/advisories/28412http://secunia.com/advisories/28457http://secunia.com/advisories/31326http://securitytracker.com/id?1019012http://wiki.rpath.com/wiki/Advisories:rPSA-2007-0257http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:011http://www.redhat.com/support/errata/RHSA-2011-0999.htmlhttp://www.securityfocus.com/archive/1/487991/100/0/threadedhttp://www.securityfocus.com/bid/26639http://www.vupen.com/english/advisories/2007/4057http://www.vupen.com/english/advisories/2008/2268http://lists.apple.com/archives/security-announce//2008/Jul/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-01/msg00002.htmlhttp://rsync.samba.org/security.html#s3_0_0http://secunia.com/advisories/27853http://secunia.com/advisories/27863http://secunia.com/advisories/28412http://secunia.com/advisories/28457http://secunia.com/advisories/31326http://securitytracker.com/id?1019012http://wiki.rpath.com/wiki/Advisories:rPSA-2007-0257http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:011http://www.redhat.com/support/errata/RHSA-2011-0999.htmlhttp://www.securityfocus.com/archive/1/487991/100/0/threadedhttp://www.securityfocus.com/bid/26639http://www.vupen.com/english/advisories/2007/4057http://www.vupen.com/english/advisories/2008/2268
2007-12-01
Published