Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Rsync Use Chroot Insecure File Creation Vulnerability

The 'rsync' utility is prone to a security vulnerability because it creates files in an insecure manner.

An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application. This may result in denial-of-service conditions; other attacks are also possible.

This issue affects versions prior to rsync 3.0.0pre6.







 

Privacy Statement
Copyright 2009, SecurityFocus