rsync Traversal Arbitrary File Creation

medium Nessus Plugin ID 12230

Synopsis

Arbitrary files may be overwritten on the remote host.

Description

The remote rsync server might be vulnerable to a path traversal issue.

An attacker may use this flaw to gain access to arbitrary files hosted outside of a module directory.

Solution

Upgrade to rsync 2.6.1 or later.

Plugin Details

Severity: Medium

ID: 12230

File Name: rsync_path_traversal.nasl

Version: 1.15

Type: remote

Family: Misc.

Published: 5/6/2004

Updated: 7/27/2018

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.4

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 4/30/2004

Reference Information

CVE: CVE-2004-0426

BID: 10247