Lucene search

K
nvd[email protected]NVD:CVE-2007-6199
HistoryDec 01, 2007 - 6:46 a.m.

CVE-2007-6199

2007-12-0106:46:00
CWE-16
web.nvd.nist.gov
4

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.4

Confidence

Low

EPSS

0.025

Percentile

90.3%

rsync before 3.0.0pre6, when running a writable rsync daemon that is not using chroot, allows remote attackers to access restricted files via unknown vectors that cause rsync to create a symlink that points outside of the module’s hierarchy.

Affected configurations

Nvd
Node
slackwareslackware_linuxMatch8.1
OR
slackwareslackware_linuxMatch9.0
OR
slackwareslackware_linuxMatch9.1
OR
slackwareslackware_linuxMatch10.0
OR
slackwareslackware_linuxMatch10.1
OR
slackwareslackware_linuxMatch10.2
OR
slackwareslackware_linuxMatch11.0
OR
slackwareslackware_linuxMatch12.0
AND
rsyncrsyncMatch2.3.1
OR
rsyncrsyncMatch2.3.2
OR
rsyncrsyncMatch2.3.2_1.2alpha
OR
rsyncrsyncMatch2.3.2_1.2arm
OR
rsyncrsyncMatch2.3.2_1.2intel
OR
rsyncrsyncMatch2.3.2_1.2m68k
OR
rsyncrsyncMatch2.3.2_1.2ppc
OR
rsyncrsyncMatch2.3.2_1.2sparc
OR
rsyncrsyncMatch2.3.2_1.3
OR
rsyncrsyncMatch2.4.0
OR
rsyncrsyncMatch2.4.1
OR
rsyncrsyncMatch2.4.3
OR
rsyncrsyncMatch2.4.4
OR
rsyncrsyncMatch2.4.5
OR
rsyncrsyncMatch2.4.6
OR
rsyncrsyncMatch2.4.8
OR
rsyncrsyncMatch2.5.0
OR
rsyncrsyncMatch2.5.1
OR
rsyncrsyncMatch2.5.2
OR
rsyncrsyncMatch2.5.3
OR
rsyncrsyncMatch2.5.4
OR
rsyncrsyncMatch2.5.5
OR
rsyncrsyncMatch2.5.6
OR
rsyncrsyncMatch2.5.7
OR
rsyncrsyncMatch2.6
OR
rsyncrsyncMatch2.6.1
OR
rsyncrsyncMatch2.6.2
OR
rsyncrsyncMatch2.6.5
OR
rsyncrsyncMatch2.6.6
OR
rsyncrsyncMatch2.6.7
OR
rsyncrsyncMatch2.6.8
OR
rsyncrsyncMatch2.6.9
VendorProductVersionCPE
slackwareslackware_linux8.1cpe:2.3:o:slackware:slackware_linux:8.1:*:*:*:*:*:*:*
slackwareslackware_linux9.0cpe:2.3:o:slackware:slackware_linux:9.0:*:*:*:*:*:*:*
slackwareslackware_linux9.1cpe:2.3:o:slackware:slackware_linux:9.1:*:*:*:*:*:*:*
slackwareslackware_linux10.0cpe:2.3:o:slackware:slackware_linux:10.0:*:*:*:*:*:*:*
slackwareslackware_linux10.1cpe:2.3:o:slackware:slackware_linux:10.1:*:*:*:*:*:*:*
slackwareslackware_linux10.2cpe:2.3:o:slackware:slackware_linux:10.2:*:*:*:*:*:*:*
slackwareslackware_linux11.0cpe:2.3:o:slackware:slackware_linux:11.0:*:*:*:*:*:*:*
slackwareslackware_linux12.0cpe:2.3:o:slackware:slackware_linux:12.0:*:*:*:*:*:*:*
rsyncrsync2.3.1cpe:2.3:a:rsync:rsync:2.3.1:*:*:*:*:*:*:*
rsyncrsync2.3.2cpe:2.3:a:rsync:rsync:2.3.2:*:*:*:*:*:*:*
Rows per page:
1-10 of 401

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.4

Confidence

Low

EPSS

0.025

Percentile

90.3%