SUSE-SA:2004:026: rsync

medium Nessus Plugin ID 14276

Synopsis

The remote host is missing a vendor-supplied security patch

Description

The remote host is missing the patch for the advisory SUSE-SA:2004:026 (rsync).


The rsync-team released an advisory about a security problem in rsync.
If rsync is running in daemon-mode and without a chroot environment it is possible for a remote attacker to trick rsyncd into creating an absolute pathname while sanitizing it.

As a result it is possible to read/write from/to files outside the rsync directory.

NOTE: SUSE LINUX ships the rsync daemon with a chroot environment enabled by default, therefore the default setup is not vulnerable.

Solution

http://www.suse.de/security/2004_26_rsync.html

Plugin Details

Severity: Medium

ID: 14276

File Name: suse_SA_2004_026.nasl

Version: 1.9

Agent: unix

Published: 8/16/2004

Updated: 1/14/2021

Supported Sensors: Nessus Agent, Nessus

Vulnerability Information

Required KB Items: Host/SuSE/rpm-list