CVE-2004-0792
rsync - unauthorised directory traversal and file access
EPSS 2.3%
描述
Directory traversal vulnerability in the sanitize_path function in util.c for rsync 2.6.2 and earlier, when chroot is disabled, allows attackers to read or write certain files.
如何修補 CVE-2004-0792
要修補 CVE-2004-0792,請將受影響套件升級到下列已修補版本。
- Debian/rsync—升級至 2.6.2-3 或更新版本
- Debian/rsync—升級至 2.5.5-0.6 或更新版本
CVE-2004-0792 正在被利用嗎?
低 — EPSS 為 2.3%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 2.6.2-3
- from 0, < 2.5.5-0.6