CVE-2017-17433

LOW3.7EPSS 1.6%
發布日:2017/12/6修改日:2025/12/3
也稱為:ALPINE-CVE-2017-17433DEBIAN-CVE-2017-17433

描述

The recv_files function in receiver.c in the daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, proceeds with certain file metadata updates before checking for a filename in the daemon_filter_list data structure, which allows remote attackers to bypass intended access restrictions.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1LOW3.7CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

參考連結(2)