Lucene search

K
nvd[email protected]NVD:CVE-2003-0962
HistoryDec 15, 2003 - 5:00 a.m.

CVE-2003-0962

2003-12-1505:00:00
web.nvd.nist.gov
1

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.9 High

AI Score

Confidence

Low

0.379 Low

EPSS

Percentile

97.2%

Heap-based buffer overflow in rsync before 2.5.7, when running in server mode, allows remote attackers to execute arbitrary code and possibly escape the chroot jail.

Affected configurations

NVD
Node
andrew_tridgellrsyncMatch2.3.1
OR
andrew_tridgellrsyncMatch2.3.2
OR
andrew_tridgellrsyncMatch2.4.0
OR
andrew_tridgellrsyncMatch2.4.1
OR
andrew_tridgellrsyncMatch2.4.3
OR
andrew_tridgellrsyncMatch2.4.4
OR
andrew_tridgellrsyncMatch2.4.5
OR
andrew_tridgellrsyncMatch2.4.6
OR
andrew_tridgellrsyncMatch2.4.8
OR
andrew_tridgellrsyncMatch2.5.0
OR
andrew_tridgellrsyncMatch2.5.1
OR
andrew_tridgellrsyncMatch2.5.2
OR
andrew_tridgellrsyncMatch2.5.3
OR
andrew_tridgellrsyncMatch2.5.4
OR
andrew_tridgellrsyncMatch2.5.5
OR
andrew_tridgellrsyncMatch2.5.6
OR
redhatrsyncMatch2.4.6-2i386
OR
redhatrsyncMatch2.4.6-5i386
OR
redhatrsyncMatch2.4.6-5ia64
OR
redhatrsyncMatch2.5.4-2i386
OR
redhatrsyncMatch2.5.5-1i386
OR
redhatrsyncMatch2.5.5-4i386
OR
engardelinuxsecure_communityMatch1.0.1
OR
engardelinuxsecure_communityMatch2.0
OR
engardelinuxsecure_linuxMatch1.1professional
OR
engardelinuxsecure_linuxMatch1.2professional
OR
engardelinuxsecure_linuxMatch1.5professional
Node
slackwareslackware_linuxMatch8.1
OR
slackwareslackware_linuxMatch9.0
OR
slackwareslackware_linuxMatch9.1
OR
slackwareslackware_linuxMatchcurrent

References

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.9 High

AI Score

Confidence

Low

0.379 Low

EPSS

Percentile

97.2%