Rsync Sanitize_path Function Module Path Escaping Vulnerability
BID:10938
Info
Rsync Sanitize_path Function Module Path Escaping Vulnerability
| Bugtraq ID: | 10938 |
| Class: | Input Validation Error |
| CVE: |
CVE-2004-0792 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 12 2004 12:00AM |
| Updated: | Jul 12 2009 06:16AM |
| Credit: | This issue was reported by the vendor. |
| Vulnerable: |
tinysofa enterprise server 2.0 Slackware Linux 10.0 Slackware Linux 9.1 Slackware Linux 9.0 Slackware Linux 8.1 Slackware Linux -current rsync rsync 2.6.2 rsync rsync 2.6.1 rsync rsync 2.6 rsync rsync 2.5.7 rsync rsync 2.5.6 rsync rsync 2.5.5 rsync rsync 2.5.4 rsync rsync 2.5.3 rsync rsync 2.5.2 rsync rsync 2.5.1 rsync rsync 2.5 .0 rsync rsync 2.4.8 rsync rsync 2.4.6 rsync rsync 2.4.5 rsync rsync 2.4.4 rsync rsync 2.4.3 rsync rsync 2.4.1 rsync rsync 2.4 .0 rsync rsync 2.3.2 -1.3 rsync rsync 2.3.2 -1.2 sparc rsync rsync 2.3.2 -1.2 PPC rsync rsync 2.3.2 -1.2 m68k rsync rsync 2.3.2 -1.2 intel rsync rsync 2.3.2 -1.2 ARM rsync rsync 2.3.2 -1.2 alpha rsync rsync 2.3.2 rsync rsync 2.3.1 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux WS 2.1 IA64 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux ES 2.1 IA64 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux AS 2.1 IA64 Redhat Enterprise Linux AS 2.1 Redhat Desktop 3.0 Redhat Advanced Workstation for the Itanium Processor 2.1 IA64 Redhat Advanced Workstation for the Itanium Processor 2.1 Avaya S8700 R2.0.1 Avaya S8700 R2.0.0 Avaya S8500 R2.0.1 Avaya S8500 R2.0.0 Avaya S8300 R2.0.1 Avaya S8300 R2.0.0 Avaya Converged Communications Server 2.0 |
| Not Vulnerable: | |
Discussion
Rsync Sanitize_path Function Module Path Escaping Vulnerability
If an rsync server is installed as a daemon with a read/write enabled module without using the 'chroot' option, it is possible that a remote attacker could read/write files outside of the configured module path. Rsync does not properly sanitize the paths when not running with chroot. The problem exists in the 'sanitize_path' function.
This could potentially be exploited to execute arbitrary code by corrupting or place arbitrary files on the system. Destruction of data could also result, possibly causing a denial of service condition. Other attacks could also occur, depending on the attacker's motives.
If an rsync server is installed as a daemon with a read/write enabled module without using the 'chroot' option, it is possible that a remote attacker could read/write files outside of the configured module path. Rsync does not properly sanitize the paths when not running with chroot. The problem exists in the 'sanitize_path' function.
This could potentially be exploited to execute arbitrary code by corrupting or place arbitrary files on the system. Destruction of data could also result, possibly causing a denial of service condition. Other attacks could also occur, depending on the attacker's motives.
Exploit / POC
Rsync Sanitize_path Function Module Path Escaping Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Rsync Sanitize_path Function Module Path Escaping Vulnerability
Solution:
Avaya has released an advisory that acknowledges this vulnerability for Avaya products. Fixes are not currently available; customers are advised to follow Red Hat (RHSA-2004:436-07) vendor recommendations to resolve this issue. Please see the referenced Avaya advisory at the following location for further details:
http://support.avaya.com/japple/css/japple?temp.groupID=128450&temp.selectedFamily=128451&temp.selectedProduct=154235&temp.selectedBucket=126655&temp.feedbackState=askForFeedback&temp.documentID=201982&PAGE=avaya.css.CSSLvl1Detail&executeTransaction=avaya.css.UsageUpdate()
Red Hat has released advisory RHSA-2004:436-07 and fixes to address this issue on Red Hat Linux Enterprise platforms. Customers who are affected by this issue are advised to apply the appropriate updates. Customers subscribed to the Red Hat Network may apply the appropriate fixes using the Red Hat Update Agent (up2date). Please see referenced advisory for additional information.
OpenPKG has released a security advisory (OpenPKG-SA-2004.037) to address this issue. Please see the referenced advisory for more information.
SUSE has released a security advisory (SUSE-SA:2004:026) to address this issue. Please see the referenced advisory for more information.
tinysofa has released a security advisory (TSSA-2004-020-ES) to address this issue. Please see the referenced advisory for further information.
Debian has released advisory DSA 538-1 to address this issue. Please see the attached advisory for further information.
Trustix has released advisory TSLSA-2004-0042 to address this issue. Please see the attached advisory for further information.
Gentoo has released updates to address this issue. Updates may be applied with the following commands:
emerge sync
emerge -pv ">=net-misc/rsync-2.6.0-r3"
emerge ">=net-misc/rsync-2.6.0-r3"
Netwosix has released advisory LNSA-#2004-0017 to address this issue. Please see the attached advisory for further information.
Mandrake has released an advisory (MDKSA-2004:083) to address this issue. Please see the referenced advisory for more information.
RedHat has released two advisories (FEDORA-2004-268, FEDORA-2004-269) to address this issue in Fedora Core 1 and Fedora Core 2. Please see the referenced advisories for more information.
Turbolinux has released an advisory (TLSA-2004-20) to address this issue. Please see the referenced advisory for more information.
RedHat has released a Fedora legacy advisory (FLSA:2003) to address various issues in rsync. This advisory fixes these issues in Red Hat Linux 7.3 and 9 running on the i386 architecture. Please see the referenced advisory for more details and information about obtaining fixes.
Slackware Linux has released an advisory (SSA:2004-285-01) along with fixes dealing with this issue. For more information please see the referenced advisory.
Contectiva Linux has released advisory CLA-2004:881 along with fixes dealing with this issue. Please see the referenced advisory for more information.
tinysofa enterprise server 2.0
rsync rsync 2.4.6
rsync rsync 2.5.4
rsync rsync 2.5.5
rsync rsync 2.5.6
rsync rsync 2.5.7
rsync rsync 2.6
rsync rsync 2.6.2
Solution:
Avaya has released an advisory that acknowledges this vulnerability for Avaya products. Fixes are not currently available; customers are advised to follow Red Hat (RHSA-2004:436-07) vendor recommendations to resolve this issue. Please see the referenced Avaya advisory at the following location for further details:
http://support.avaya.com/japple/css/japple?temp.groupID=128450&temp.selectedFamily=128451&temp.selectedProduct=154235&temp.selectedBucket=126655&temp.feedbackState=askForFeedback&temp.documentID=201982&PAGE=avaya.css.CSSLvl1Detail&executeTransaction=avaya.css.UsageUpdate()
Red Hat has released advisory RHSA-2004:436-07 and fixes to address this issue on Red Hat Linux Enterprise platforms. Customers who are affected by this issue are advised to apply the appropriate updates. Customers subscribed to the Red Hat Network may apply the appropriate fixes using the Red Hat Update Agent (up2date). Please see referenced advisory for additional information.
OpenPKG has released a security advisory (OpenPKG-SA-2004.037) to address this issue. Please see the referenced advisory for more information.
SUSE has released a security advisory (SUSE-SA:2004:026) to address this issue. Please see the referenced advisory for more information.
tinysofa has released a security advisory (TSSA-2004-020-ES) to address this issue. Please see the referenced advisory for further information.
Debian has released advisory DSA 538-1 to address this issue. Please see the attached advisory for further information.
Trustix has released advisory TSLSA-2004-0042 to address this issue. Please see the attached advisory for further information.
Gentoo has released updates to address this issue. Updates may be applied with the following commands:
emerge sync
emerge -pv ">=net-misc/rsync-2.6.0-r3"
emerge ">=net-misc/rsync-2.6.0-r3"
Netwosix has released advisory LNSA-#2004-0017 to address this issue. Please see the attached advisory for further information.
Mandrake has released an advisory (MDKSA-2004:083) to address this issue. Please see the referenced advisory for more information.
RedHat has released two advisories (FEDORA-2004-268, FEDORA-2004-269) to address this issue in Fedora Core 1 and Fedora Core 2. Please see the referenced advisories for more information.
Turbolinux has released an advisory (TLSA-2004-20) to address this issue. Please see the referenced advisory for more information.
RedHat has released a Fedora legacy advisory (FLSA:2003) to address various issues in rsync. This advisory fixes these issues in Red Hat Linux 7.3 and 9 running on the i386 architecture. Please see the referenced advisory for more details and information about obtaining fixes.
Slackware Linux has released an advisory (SSA:2004-285-01) along with fixes dealing with this issue. For more information please see the referenced advisory.
Contectiva Linux has released advisory CLA-2004:881 along with fixes dealing with this issue. Please see the referenced advisory for more information.
tinysofa enterprise server 2.0
-
tinysofa rsync-2.6.2-2ts.i386.rpm
http://http.tinysofa.org/pub/tinysofa/updates/server-2.0/i386/tinysofa /rpms.updates/rsync-2.6.2-2ts.i386.rpm
rsync rsync 2.4.6
-
TurboLinux rsync-2.6.2-2.i586.rpm
TurboLinux 7 Server
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/7/updat es/RPMS/rsync-2.6.2-2.i586.rpm -
TurboLinux rsync-2.6.2-2.i586.rpm
TurboLinux 7 Workstation
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/7/ updates/RPMS/rsync-2.6.2-2.i586.rpm
rsync rsync 2.5.4
-
TurboLinux rsync-2.6.2-2.i586.rpm
TurboLinux 8 Workstation
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/8/ updates/RPMS/rsync-2.6.2-2.i586.rpm
rsync rsync 2.5.5
-
Debian rsync_2.5.5-0.6_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/r/rsync/rsync_2.5.5-0.6_a lpha.deb -
Debian rsync_2.5.5-0.6_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/r/rsync/rsync_2.5.5-0.6_a rm.deb -
Debian rsync_2.5.5-0.6_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/r/rsync/rsync_2.5.5-0.6_h ppa.deb -
Debian rsync_2.5.5-0.6_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/r/rsync/rsync_2.5.5-0.6_i 386.deb -
Debian rsync_2.5.5-0.6_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/r/rsync/rsync_2.5.5-0.6_i a64.deb -
Debian rsync_2.5.5-0.6_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/r/rsync/rsync_2.5.5-0.6_m 68k.deb -
Debian rsync_2.5.5-0.6_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/r/rsync/rsync_2.5.5-0.6_m ips.deb -
Debian rsync_2.5.5-0.6_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/r/rsync/rsync_2.5.5-0.6_m ipsel.deb -
Debian rsync_2.5.5-0.6_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/r/rsync/rsync_2.5.5-0.6_p owerpc.deb -
Debian rsync_2.5.5-0.6_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/r/rsync/rsync_2.5.5-0.6_s 390.deb -
Debian rsync_2.5.5-0.6_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/r/rsync/rsync_2.5.5-0.6_s parc.deb -
Mandrake rsync-2.5.5-5.3.C21mdk.i586.rpm
Mandrake Corporate Server 2.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake rsync-2.5.5-5.3.C21mdk.x86_64.rpm
Mandrake Corporate Server 2.1/x86_64
http://www.mandrakesecure.net/en/ftp.php -
SuSE rsync-2.6.2-25.i586.patch.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.1/rpm/i586/rsync-2.6.2-25.i5 86.patch.rpm -
SuSE rsync-2.6.2-25.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.1/rpm/i586/rsync-2.6.2-25.i5 86.rpm -
TurboLinux rsync-2.6.2-2.i586.rpm
TurboLinux 10 Desktop & 10 F...
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Desktop/10/upd ates/RPMS/rsync-2.6.2-2.i586.rpm -
TurboLinux rsync-2.6.2-2.i586.rpm
TurboLinux 8 Server
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/8/updat es/RPMS/rsync-2.6.2-2.i586.rpm
rsync rsync 2.5.6
-
Conectiva rsync-2.5.7-13508U90_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/SRPMS/rsync-2.5.7-13508U90_2cl.i 386.rpm -
Fedora rsync-2.5.7-5.fc1.1.i386.rpm
Redhat Fedora Core 1
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/ -
Fedora rsync-debuginfo-2.5.7-5.fc1.1.i386.rpm
Redhat Fedora Core 1
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/ -
Mandrake rsync-2.5.7-0.3.91mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake rsync-2.5.7-0.3.91mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake rsync-2.5.7-0.3.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake rsync-2.5.7-0.3.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Slackware rsync-2.6.3-i386-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-9.0/patches/packages/r sync-2.6.3-i386-1.tgz -
Slackware rsync-2.6.3-i486-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/r sync-2.6.3-i486-1.tgz -
SuSE rsync-2.6.2-26.i586.patch.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.2/rpm/i586/rsync-2.6.2-26.i5 86.patch.rpm -
SuSE rsync-2.6.2-26.i586.patch.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/rsync-2.6.2-26.i5 86.patch.rpm -
SuSE rsync-2.6.2-26.x86_64.patch.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.0/rpm/x86_64/rsync-2.6.2-2 6.x86_64.patch.rpm -
SuSE rsync-2.6.2-26.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.2/rpm/i586/rsync-2.6.2-26.i5 86.rpm -
SuSE rsync-2.6.2-26.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/rsync-2.6.2-26.i5 86.rpm -
SuSE rsync-2.6.2-26.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.0/rpm/x86_64/rsync-2.6.2-2 6.x86_64.rpm
rsync rsync 2.5.7
-
Fedora rsync-2.5.7-5.fc1.1.x86_64.rpm
Redhat Fedora Core 1
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/ -
Fedora rsync-debuginfo-2.5.7-5.fc1.1.x86_64.rpm
Redhat Fedora Core 1
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/ -
RedHat rsync-2.5.7-2.legacy.7x.i386.rpm
RedHat Linux 7.3
http://download.fedoralegacy.org/redhat/7.3/updates/i386/rsync-2.5.7-2 .legacy.7x.i386.rpm -
RedHat rsync-2.5.7-2.legacy.9.i386.rpm
RedHat Linux 9
http://download.fedoralegacy.org/redhat/9/updates/i386/rsync-2.5.7-2.l egacy.9.i386.rpm
rsync rsync 2.6
-
Mandrake rsync-2.6.0-1.2.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake rsync-2.6.0-1.2.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
OpenPKG rsync-2.6.0-2.0.2.src.rpm
ftp://ftp.openpkg.org/release/2.0/UPD/rsync-2.6.0-2.0.2.src.rpm -
SuSE rsync-2.6.2-8.9.i586.patch.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/rsync-2.6.2-8.9.i 586.patch.rpm -
SuSE rsync-2.6.2-8.9.x86_64.patch.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/rsync-2.6.2-8 .9.x86_64.patch.rpm -
SuSE rsync-2.6.2-8.9.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/rsync-2.6.2-8.9.i 586.rpm -
SuSE rsync-2.6.2-8.9.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/rsync-2.6.2-8 .9.x86_64.rpm
rsync rsync 2.6.2
-
Conectiva rsync-2.6.3-59134U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/rsync-2.6.3-59134U10_1cl.i 386.rpm -
Fedora rsync-2.6.2-1.fc2.0.i386.rpm
Redhat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora rsync-2.6.2-1.fc2.0.x86_64.rpm
Redhat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora rsync-debuginfo-2.6.2-1.fc2.0.i386.rpm
Redhat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora rsync-debuginfo-2.6.2-1.fc2.0.x86_64.rpm
Redhat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Netwosix 0017/nepote
Netwosix 1.0 Netwosix 1.1 - rsync upgrade
http://download.netwosix.org/0017/nepote -
OpenPKG rsync-2.6.2-2.1.1.src.rpm
ftp://ftp.openpkg.org/release/2.1/UPD/rsync-2.6.2-2.1.1.src.rpm -
Slackware rsync-2.6.3-i486-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-10.0/patches/packages/ rsync-2.6.3-i486-1.tgz -
Trustix rsync-2.6.2-0.2tr.i586.rpm
Trustix Secure Linux 2.0
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix rsync-2.6.2-2tr.i586.rpm
Trustix Secure Linux 2.1 & Enterprise Server 2
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix rsync-2.6.2-3tr.i586.rpm
Trustix Secure Linux 1.5
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix rsync-server-2.6.2-0.2tr.i586.rpm
Trustix Secure Linux 2.0
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix rsync-server-2.6.2-2tr.i586.rpm
Trustix Secure Linux 2.1 & Enterprise Server 2
ftp://ftp.trustix.org/pub/trustix/updates/
References
Rsync Sanitize_path Function Module Path Escaping Vulnerability
References:
References: