Rsync Use Chroot Insecure File Creation Vulnerability
BID:26638
Info
Rsync Use Chroot Insecure File Creation Vulnerability
| Bugtraq ID: | 26638 |
| Class: | Design Error |
| CVE: |
CVE-2007-6199 |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 29 2007 12:00AM |
| Updated: | Mar 19 2015 09:43AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise Desktop 10 SP1 SuSE SUSE Linux Enterprise Desktop 10 SuSE openSUSE 10.3 Slackware Linux 10.2 Slackware Linux 10.1 Slackware Linux 10.0 Slackware Linux 9.1 Slackware Linux 9.0 Slackware Linux 8.1 Slackware Linux 12.0 Slackware Linux 11.0 S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. openSUSE 10.2 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux POS 9 S.u.S.E. Novell Linux Desktop SDK 9.0 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Desktop 10 S.u.S.E. Linux 10.1 x86-64 S.u.S.E. Linux 10.1 x86 S.u.S.E. Linux 10.1 ppc S.u.S.E. Linux 10.0 x86-64 S.u.S.E. Linux 10.0 x86 S.u.S.E. Linux 10.0 ppc rsync rsync 2.6.9 rsync rsync 2.6.8 rsync rsync 2.6.7 rsync rsync 2.6.6 rsync rsync 2.6.5 rsync rsync 2.6.2 rsync rsync 2.6.1 rsync rsync 2.6 rsync rsync 2.5.7 rsync rsync 2.5.6 rsync rsync 2.5.5 rsync rsync 2.5.4 rsync rsync 2.5.3 rsync rsync 2.5.2 rsync rsync 2.5.1 rsync rsync 2.5 .0 rsync rsync 2.4.8 rsync rsync 2.4.6 rsync rsync 2.4.5 rsync rsync 2.4.4 rsync rsync 2.4.3 rsync rsync 2.4.1 rsync rsync 2.4 .0 rsync rsync 2.3.2 -1.3 rsync rsync 2.3.2 -1.2 sparc rsync rsync 2.3.2 -1.2 PPC rsync rsync 2.3.2 -1.2 m68k rsync rsync 2.3.2 -1.2 intel rsync rsync 2.3.2 -1.2 ARM rsync rsync 2.3.2 -1.2 alpha rsync rsync 2.3.2 rsync rsync 2.3.1 rPath rPath Linux 1 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 Mandriva Linux Mandrake 2007.0 x86_64 Mandriva Linux Mandrake 2007.0 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 4.0 Foresight Linux Foresight Linux 1.1 Apple Mac OS X Server 10.5.4 Apple Mac OS X Server 10.5.3 Apple Mac OS X Server 10.5.2 Apple Mac OS X Server 10.5.1 Apple Mac OS X Server 10.4.11 Apple Mac OS X Server 10.4.10 Apple Mac OS X Server 10.4.9 Apple Mac OS X Server 10.4.8 Apple Mac OS X Server 10.4.7 Apple Mac OS X Server 10.4.6 Apple Mac OS X Server 10.4.5 Apple Mac OS X Server 10.4.4 Apple Mac OS X Server 10.4.3 Apple Mac OS X Server 10.4.2 Apple Mac OS X Server 10.4.1 Apple Mac OS X Server 10.4 Apple Mac OS X Server 10.5 Apple Mac OS X 10.5.4 Apple Mac OS X 10.5.3 Apple Mac OS X 10.5.2 Apple Mac OS X 10.5.1 Apple Mac OS X 10.4.11 Apple Mac OS X 10.4.10 Apple Mac OS X 10.4.9 Apple Mac OS X 10.4.8 Apple Mac OS X 10.4.7 Apple Mac OS X 10.4.6 Apple Mac OS X 10.4.5 Apple Mac OS X 10.4.4 Apple Mac OS X 10.4.3 Apple Mac OS X 10.4.2 Apple Mac OS X 10.4.1 Apple Mac OS X 10.4 Apple Mac OS X 10.5 |
| Not Vulnerable: |
rsync rsync 3.0.0pre6 |
Discussion
Rsync Use Chroot Insecure File Creation Vulnerability
The 'rsync' utility is prone to a security vulnerability because it creates files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application. This may result in denial-of-service conditions; other attacks are also possible.
This issue affects versions prior to rsync 3.0.0pre6.
The 'rsync' utility is prone to a security vulnerability because it creates files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application. This may result in denial-of-service conditions; other attacks are also possible.
This issue affects versions prior to rsync 3.0.0pre6.
Exploit / POC
Rsync Use Chroot Insecure File Creation Vulnerability
An attacker uses readily available commands to exploit this issue.
An attacker uses readily available commands to exploit this issue.
Solution / Fix
Rsync Use Chroot Insecure File Creation Vulnerability
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Apple Mac OS X 10.4.11
Apple Mac OS X Server 10.4.11
Apple Mac OS X 10.5.4
Apple Mac OS X Server 10.5.4
rsync rsync 2.3.1
rsync rsync 2.3.2 -1.2 m68k
rsync rsync 2.3.2 -1.2 PPC
rsync rsync 2.3.2 -1.2 intel
rsync rsync 2.3.2 -1.2 sparc
rsync rsync 2.3.2
rsync rsync 2.3.2 -1.2 ARM
rsync rsync 2.4 .0
rsync rsync 2.4.1
rsync rsync 2.4.4
rsync rsync 2.4.5
rsync rsync 2.4.6
rsync rsync 2.4.8
rsync rsync 2.5.1
rsync rsync 2.5.2
rsync rsync 2.5.4
rsync rsync 2.5.5
rsync rsync 2.5.6
rsync rsync 2.5.7
rsync rsync 2.6.1
rsync rsync 2.6.2
rsync rsync 2.6.5
rsync rsync 2.6.7
rsync rsync 2.6.8
rsync rsync 2.6.9
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Apple Mac OS X 10.4.11
-
Apple SecUpd2008-005Intel.dmg
For Mac OS X v10.4.11 (Intel)
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=20387&cat= 1&platform=osx&method=sa/SecUpd2008-005Intel.dmg -
Apple SecUpd2008-005PPC.dmg
For Mac OS X v10.4.11 (PPC)
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=20386&cat= 1&platform=osx&method=sa/SecUpd2008-005PPC.dmg
Apple Mac OS X Server 10.4.11
-
Apple SecUpdSrvr2008-005PPC.dmg
For Mac OS X Server v10.4.11 (PPC)
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=20384&cat= 1&platform=osx&method=sa/SecUpdSrvr2008-005PPC.dmg -
Apple SecUpdSrvr2008-005Univ.dmg
For Mac OS X Server v10.4.11 (Universal)
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=20385&cat= 1&platform=osx&method=sa/SecUpdSrvr2008-005Univ.dmg
Apple Mac OS X 10.5.4
-
Apple SecUpd2008-005.dmg
For Mac OS X v10.5.4 and Mac OS X Server 10.5.4
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=20388&cat= 1&platform=osx&method=sa/SecUpd2008-005.dmg
Apple Mac OS X Server 10.5.4
-
Apple SecUpd2008-005.dmg
For Mac OS X v10.5.4 and Mac OS X Server 10.5.4
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=20388&cat= 1&platform=osx&method=sa/SecUpd2008-005.dmg
rsync rsync 2.3.1
-
rsync rsync-3.0.0pre6.tar.gz
http://rsync.samba.org/ftp/rsync/rsync-3.0.0pre6.tar.gz
rsync rsync 2.3.2 -1.2 m68k
-
rsync rsync-3.0.0pre6.tar.gz
http://rsync.samba.org/ftp/rsync/rsync-3.0.0pre6.tar.gz
rsync rsync 2.3.2 -1.2 PPC
-
rsync rsync-3.0.0pre6.tar.gz
http://rsync.samba.org/ftp/rsync/rsync-3.0.0pre6.tar.gz
rsync rsync 2.3.2 -1.2 intel
-
rsync rsync-3.0.0pre6.tar.gz
http://rsync.samba.org/ftp/rsync/rsync-3.0.0pre6.tar.gz
rsync rsync 2.3.2 -1.2 sparc
-
rsync rsync-3.0.0pre6.tar.gz
http://rsync.samba.org/ftp/rsync/rsync-3.0.0pre6.tar.gz
rsync rsync 2.3.2
-
rsync rsync-3.0.0pre6.tar.gz
http://rsync.samba.org/ftp/rsync/rsync-3.0.0pre6.tar.gz
rsync rsync 2.3.2 -1.2 ARM
-
rsync rsync-3.0.0pre6.tar.gz
http://rsync.samba.org/ftp/rsync/rsync-3.0.0pre6.tar.gz
rsync rsync 2.4 .0
-
rsync rsync-3.0.0pre6.tar.gz
http://rsync.samba.org/ftp/rsync/rsync-3.0.0pre6.tar.gz
rsync rsync 2.4.1
-
rsync rsync-3.0.0pre6.tar.gz
http://rsync.samba.org/ftp/rsync/rsync-3.0.0pre6.tar.gz
rsync rsync 2.4.4
-
rsync rsync-3.0.0pre6.tar.gz
http://rsync.samba.org/ftp/rsync/rsync-3.0.0pre6.tar.gz
rsync rsync 2.4.5
-
rsync rsync-3.0.0pre6.tar.gz
http://rsync.samba.org/ftp/rsync/rsync-3.0.0pre6.tar.gz
rsync rsync 2.4.6
-
rsync rsync-3.0.0pre6.tar.gz
http://rsync.samba.org/ftp/rsync/rsync-3.0.0pre6.tar.gz
rsync rsync 2.4.8
-
rsync rsync-3.0.0pre6.tar.gz
http://rsync.samba.org/ftp/rsync/rsync-3.0.0pre6.tar.gz
rsync rsync 2.5.1
-
rsync rsync-3.0.0pre6.tar.gz
http://rsync.samba.org/ftp/rsync/rsync-3.0.0pre6.tar.gz
rsync rsync 2.5.2
-
rsync rsync-3.0.0pre6.tar.gz
http://rsync.samba.org/ftp/rsync/rsync-3.0.0pre6.tar.gz
rsync rsync 2.5.4
-
rsync rsync-3.0.0pre6.tar.gz
http://rsync.samba.org/ftp/rsync/rsync-3.0.0pre6.tar.gz
rsync rsync 2.5.5
-
rsync rsync-3.0.0pre6.tar.gz
http://rsync.samba.org/ftp/rsync/rsync-3.0.0pre6.tar.gz
rsync rsync 2.5.6
-
rsync rsync-3.0.0pre6.tar.gz
http://rsync.samba.org/ftp/rsync/rsync-3.0.0pre6.tar.gz
rsync rsync 2.5.7
-
rsync rsync-3.0.0pre6.tar.gz
http://rsync.samba.org/ftp/rsync/rsync-3.0.0pre6.tar.gz
rsync rsync 2.6.1
-
rsync rsync-3.0.0pre6.tar.gz
http://rsync.samba.org/ftp/rsync/rsync-3.0.0pre6.tar.gz
rsync rsync 2.6.2
-
rsync rsync-3.0.0pre6.tar.gz
http://rsync.samba.org/ftp/rsync/rsync-3.0.0pre6.tar.gz
rsync rsync 2.6.5
-
rsync rsync-3.0.0pre6.tar.gz
http://rsync.samba.org/ftp/rsync/rsync-3.0.0pre6.tar.gz
rsync rsync 2.6.7
-
rsync rsync-3.0.0pre6.tar.gz
http://rsync.samba.org/ftp/rsync/rsync-3.0.0pre6.tar.gz
rsync rsync 2.6.8
-
rsync rsync-3.0.0pre6.tar.gz
http://rsync.samba.org/ftp/rsync/rsync-3.0.0pre6.tar.gz
rsync rsync 2.6.9
-
rsync rsync-3.0.0pre6.tar.gz
http://rsync.samba.org/ftp/rsync/rsync-3.0.0pre6.tar.gz
References
Rsync Use Chroot Insecure File Creation Vulnerability
References:
References: