Synopsis
The remote host is missing a vendor-supplied security patch
Description
The remote host is missing the patch for the advisory SUSE-SA:2004:026 (rsync).
The rsync-team released an advisory about a security problem in rsync.
If rsync is running in daemon-mode and without a chroot environment it is possible for a remote attacker to trick rsyncd into creating an absolute pathname while sanitizing it.
As a result it is possible to read/write from/to files outside the rsync directory.
NOTE: SUSE LINUX ships the rsync daemon with a chroot environment enabled by default, therefore the default setup is not vulnerable.
Solution
http://www.suse.de/security/2004_26_rsync.html
Plugin Details
File Name: suse_SA_2004_026.nasl
Agent: unix
Supported Sensors: Nessus Agent, Nessus
Vulnerability Information
Required KB Items: Host/SuSE/rpm-list