Rsync Daemon Excludes Multiple File Access Vulnerabilities
BID:26639
Info
Rsync Daemon Excludes Multiple File Access Vulnerabilities
| Bugtraq ID: | 26639 |
| Class: | Access Validation Error |
| CVE: |
CVE-2007-6200 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 29 2007 12:00AM |
| Updated: | Mar 19 2015 08:30AM |
| Credit: | These issues were disclosed by the vendor. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE Suse Linux Enterprise Desktop 10 SP1 SuSE Suse Linux Enterprise Desktop 10 SuSE Linux Desktop 10 SuSE Linux 10.1 x86-64 SuSE Linux 10.1 x86 SuSE Linux 10.1 ppc SuSE Linux 10.0 x86-64 SuSE Linux 10.0 x86 SuSE Linux 10.0 ppc Slackware Linux 10.2 Slackware Linux 10.1 Slackware Linux 10.0 Slackware Linux 9.1 Slackware Linux 9.0 Slackware Linux 8.1 Slackware Linux 12.0 Slackware Linux 11.0 S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. openSUSE 10.3 S.u.S.E. openSUSE 10.2 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux POS 9 S.u.S.E. Novell Linux Desktop SDK 9.0 S.u.S.E. Novell Linux Desktop 9.0 rsync rsync 2.6.9 rsync rsync 2.6.8 rsync rsync 2.6.7 rsync rsync 2.6.6 rsync rsync 2.6.5 rsync rsync 2.6.2 rsync rsync 2.6.1 rsync rsync 2.6 rsync rsync 2.5.7 rsync rsync 2.5.6 rsync rsync 2.5.5 rsync rsync 2.5.4 rsync rsync 2.5.3 rsync rsync 2.5.2 rsync rsync 2.5.1 rsync rsync 2.5 .0 rsync rsync 2.4.8 rsync rsync 2.4.6 rsync rsync 2.4.5 rsync rsync 2.4.4 rsync rsync 2.4.3 rsync rsync 2.4.1 rsync rsync 2.4 .0 rsync rsync 2.3.2 -1.3 rsync rsync 2.3.2 -1.2 sparc rsync rsync 2.3.2 -1.2 PPC rsync rsync 2.3.2 -1.2 m68k rsync rsync 2.3.2 -1.2 intel rsync rsync 2.3.2 -1.2 ARM rsync rsync 2.3.2 -1.2 alpha rsync rsync 2.3.2 rsync rsync 2.3.1 rsync rsync 3.0.0pre6 rPath rPath Linux 1 Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux 5 Server Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 Mandriva Linux Mandrake 2007.0 x86_64 Mandriva Linux Mandrake 2007.0 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 4.0 Foresight Linux Foresight Linux 1.1 Avaya IQ 5.2 Avaya IQ 5.1.1 Avaya IQ 5.1 Avaya IQ 5 Avaya Communication Server 1000M Signaling Server 7.5 Avaya Communication Server 1000M Signaling Server 7.0 Avaya Communication Server 1000M Signaling Server 6.0 Avaya Communication Server 1000M 7.5 Avaya Communication Server 1000M 7.0 Avaya Communication Server 1000M 6.0 Avaya Communication Server 1000E Signaling Server 7.5 Avaya Communication Server 1000E Signaling Server 7.0 Avaya Communication Server 1000E Signaling Server 6.0 Avaya Communication Server 1000E 7.5 Avaya Communication Server 1000E 7.0 Avaya Communication Server 1000E 6.0 Avaya Aura System Manager 6.3 Avaya Aura System Manager 6.2.3 Avaya Aura System Manager 6.1.5 Avaya Aura System Manager 6.1.3 Avaya Aura System Manager 6.1.2 Avaya Aura System Manager 6.1.1 Avaya Aura System Manager 6.0 Avaya Aura System Manager 5.2 Avaya Aura Messaging 6.0.1 Avaya Aura Messaging 6.0 Avaya Aura Communication Manager Utility Services 6.1 Avaya Aura Communication Manager Utility Services 6.0 Avaya Aura Communication Manager 6.0.1 Avaya Aura Communication Manager 6.0 Avaya Aura Application Server 5300 SIP Core 2.0 Avaya Aura Application Server 2.0 Apple Mac OS X Server 10.5.4 Apple Mac OS X Server 10.5.3 Apple Mac OS X Server 10.5.2 Apple Mac OS X Server 10.5.1 Apple Mac OS X Server 10.4.11 Apple Mac OS X Server 10.4.10 Apple Mac OS X Server 10.4.9 Apple Mac OS X Server 10.4.8 Apple Mac OS X Server 10.4.7 Apple Mac OS X Server 10.4.6 Apple Mac OS X Server 10.4.5 Apple Mac OS X Server 10.4.4 Apple Mac OS X Server 10.4.3 Apple Mac OS X Server 10.4.2 Apple Mac OS X Server 10.4.1 Apple Mac OS X Server 10.4 Apple Mac OS X Server 10.5 Apple Mac OS X 10.5.4 Apple Mac OS X 10.5.3 Apple Mac OS X 10.5.2 Apple Mac OS X 10.5.1 Apple Mac OS X 10.4.11 Apple Mac OS X 10.4.10 Apple Mac OS X 10.4.9 Apple Mac OS X 10.4.8 Apple Mac OS X 10.4.7 Apple Mac OS X 10.4.6 Apple Mac OS X 10.4.5 Apple Mac OS X 10.4.4 Apple Mac OS X 10.4.3 Apple Mac OS X 10.4.2 Apple Mac OS X 10.4.1 Apple Mac OS X 10.4 Apple Mac OS X 10.5 |
| Not Vulnerable: |
Avaya Aura Messaging 6.2 Avaya Aura Communication Manager Utility Services 6.2 Avaya Aura Communication Manager 6.2 Avaya Aura Application Server 5300 SIP Core 2.0 PB28 Avaya Aura Application Server 5300 SIP Core 2.0 PB26 Avaya Aura Application Server 5300 SIP Core 2.0 PB25 Avaya Aura Application Server 5300 SIP Core 2.0 PB23 Avaya Aura Application Server 5300 SIP Core 2.0 PB19 Avaya Aura Application Server 5300 SIP Core 2.0 PB16 |
Discussion
Rsync Daemon Excludes Multiple File Access Vulnerabilities
The 'rsync' daemon is prone to multiple file-access vulnerabilities because it fails to properly validate 'exclude'-type options set in the daemon's configuration file 'rsyncd.conf'.
Attackers can exploit these issues to read sensitive information or overwrite files with writable permissions.
The 'rsync' daemon is prone to multiple file-access vulnerabilities because it fails to properly validate 'exclude'-type options set in the daemon's configuration file 'rsyncd.conf'.
Attackers can exploit these issues to read sensitive information or overwrite files with writable permissions.
Exploit / POC
Rsync Daemon Excludes Multiple File Access Vulnerabilities
Attackers can use rsync as a client to access vulnerable rsync servers to exploit these issues. Attackers must be aware of the hidden files' names to access them.
Attackers can use rsync as a client to access vulnerable rsync servers to exploit these issues. Attackers must be aware of the hidden files' names to access them.
Solution / Fix
Rsync Daemon Excludes Multiple File Access Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Apple Mac OS X 10.4.11
Apple Mac OS X Server 10.4.11
Apple Mac OS X 10.5.4
Solution:
Updates are available. Please see the references for more information.
Apple Mac OS X 10.4.11
-
Apple SecUpd2008-005Intel.dmg
For Mac OS X v10.4.11 (Intel)
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=20387&cat= 1&platform=osx&method=sa/SecUpd2008-005Intel.dmg -
Apple SecUpd2008-005PPC.dmg
For Mac OS X v10.4.11 (PPC)
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=20386&cat= 1&platform=osx&method=sa/SecUpd2008-005PPC.dmg
Apple Mac OS X Server 10.4.11
-
Apple SecUpdSrvr2008-005PPC.dmg
For Mac OS X Server v10.4.11 (PPC)
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=20384&cat= 1&platform=osx&method=sa/SecUpdSrvr2008-005PPC.dmg -
Apple SecUpdSrvr2008-005Univ.dmg
For Mac OS X Server v10.4.11 (Universal)
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=20385&cat= 1&platform=osx&method=sa/SecUpdSrvr2008-005Univ.dmg
Apple Mac OS X 10.5.4
-
Apple SecUpd2008-005.dmg
For Mac OS X v10.5.4 and Mac OS X Server 10.5.4
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=20388&cat= 1&platform=osx&method=sa/SecUpd2008-005.dmg
References
Rsync Daemon Excludes Multiple File Access Vulnerabilities
References:
References:
- rsync Homepage (rsync)
- rsync Security Advisories (rsync)
- rsync security, bug fix, and enhancement update (RHSA-2011-0999) (Avaya Inc.)