rsync I/O Functions Multiple Signedness Errors RCE

Synopsis :

Arbitrary code can be run on the remote server.

Description :

The remote rsync server is affected by multiple signedness errors in
the I/O functions. An unauthenticated, remote attacker can exploit
these to cause a denial of service or execute arbitrary code.

Solution :

Upgrade to rsync version 2.5.2 or later.

Risk factor :

Critical / CVSS Base Score : 10.0
CVSS Temporal Score : 8.3
Public Exploit Available : true

Family: Gain a shell remotely

Nessus Plugin ID: 11390 ()

Bugtraq ID: 3958

CVE ID: CVE-2002-0048