Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Debian Woody DSA 538-1 Moderate: Rsync Path Issue Access Risk

debian
Calendar Grey August 20, 2004
Debian Logo
Debian Security Advisory DSA 538-1 This email address is being protected from spambots. You need Jav
The rsync developers have discoverd a security related problem in rsync which offers an attacker to access files outside of the defined directory.

Summary

The rsync developers have discoverd a security related problem in
rsync, a fast remote file copy program, which offers an attacker to
access files outside of the defined directory. To exploit this
path-sanitizing bug, rsync has to run in daemon mode with the chroot
option being disabled. It does not affect the normal send/receive
filenames that specify what files should be transferred. It does
affect certain option paths that cause auxilliary files to be read or
written.

For the stable distribution (woody) this problem has been fixed in
version 2.5.5-0.6.

For the unstable distribution (sid) this problem has been fixed in
version 2.6.2-3.

We recommend that you upgrade your rsync package.


Upgrade Instructions
- --------------------

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
will update the internal database
apt-get upgrade
w...

Read the Full Advisory

Package: rsync

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here