CVE
- Id
- 8854
- CVE No.
- CVE-2004-0426
- Status
- Candidate
- Description
- rsync before 2.6.1 does not properly sanitize paths when running a read/write daemon without using chroot, which allows remote attackers to write files outside of the module"s path.
- Phase
- Assigned (20040429)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
56357 | 8854 | CVE-2004-0426 | CONFIRM:http://rsync.samba.org/ | View |
56358 | 8854 | CVE-2004-0426 | DEBIAN:DSA-499 | View |
56359 | 8854 | CVE-2004-0426 | URL:http://www.debian.org/security/2004/dsa-499 | View |
56360 | 8854 | CVE-2004-0426 | GENTOO:GLSA-200407-10 | View |
56361 | 8854 | CVE-2004-0426 | URL:http://www.gentoo.org/security/en/glsa/glsa-200407-10.xml | View |
56362 | 8854 | CVE-2004-0426 | MANDRAKE:MDKSA-2004:042 | View |
56363 | 8854 | CVE-2004-0426 | URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:042 | View |
56364 | 8854 | CVE-2004-0426 | REDHAT:RHSA-2004:192 | View |
56365 | 8854 | CVE-2004-0426 | URL:http://www.redhat.com/support/errata/RHSA-2004-192.html | View |
56366 | 8854 | CVE-2004-0426 | SLACKWARE:SSA:2004-124-01 | View |
56367 | 8854 | CVE-2004-0426 | URL:http://www.slackware.org/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.403462 | View |
56368 | 8854 | CVE-2004-0426 | TRUSTIX:TSL-2004-0024 | View |
56369 | 8854 | CVE-2004-0426 | URL:http://www.trustix.net/errata/misc/2004/TSL-2004-0024-rsync.asc.txt | View |
56370 | 8854 | CVE-2004-0426 | BUGTRAQ:20040521 [OpenPKG-SA-2004.025] OpenPKG Security Advisory (rsync) | View |
56371 | 8854 | CVE-2004-0426 | URL:http://marc.info/?l=bugtraq&m=108515912212018&w=2 | View |
56372 | 8854 | CVE-2004-0426 | CIAC:O-134 | View |
56373 | 8854 | CVE-2004-0426 | URL:http://www.ciac.org/ciac/bulletins/o-134.shtml | View |
56374 | 8854 | CVE-2004-0426 | CIAC:O-212 | View |
56375 | 8854 | CVE-2004-0426 | URL:http://www.ciac.org/ciac/bulletins/o-212.shtml | View |
56376 | 8854 | CVE-2004-0426 | BID:10247 | View |
56377 | 8854 | CVE-2004-0426 | URL:http://www.securityfocus.com/bid/10247 | View |
56378 | 8854 | CVE-2004-0426 | OVAL:oval:org.mitre.oval:def:9495 | View |
56379 | 8854 | CVE-2004-0426 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9495 | View |
56380 | 8854 | CVE-2004-0426 | SECUNIA:11514 | View |
56381 | 8854 | CVE-2004-0426 | URL:http://secunia.com/advisories/11514 | View |
56382 | 8854 | CVE-2004-0426 | SECUNIA:11515 | View |
56383 | 8854 | CVE-2004-0426 | URL:http://secunia.com/advisories/11515 | View |
56384 | 8854 | CVE-2004-0426 | SECUNIA:11523 | View |
56385 | 8854 | CVE-2004-0426 | URL:http://secunia.com/advisories/11523 | View |
56386 | 8854 | CVE-2004-0426 | SECUNIA:11537 | View |
56387 | 8854 | CVE-2004-0426 | URL:http://secunia.com/advisories/11537 | View |
56388 | 8854 | CVE-2004-0426 | SECUNIA:11583 | View |
56389 | 8854 | CVE-2004-0426 | URL:http://secunia.com/advisories/11583 | View |
56390 | 8854 | CVE-2004-0426 | SECUNIA:11669 | View |
56391 | 8854 | CVE-2004-0426 | URL:http://secunia.com/advisories/11669 | View |
56392 | 8854 | CVE-2004-0426 | SECUNIA:11688 | View |
56393 | 8854 | CVE-2004-0426 | URL:http://secunia.com/advisories/11688 | View |
56394 | 8854 | CVE-2004-0426 | SECUNIA:11993 | View |
56395 | 8854 | CVE-2004-0426 | URL:http://secunia.com/advisories/11993 | View |
56396 | 8854 | CVE-2004-0426 | SECUNIA:12054 | View |
56397 | 8854 | CVE-2004-0426 | URL:http://secunia.com/advisories/12054 | View |
56398 | 8854 | CVE-2004-0426 | OVAL:oval:org.mitre.oval:def:967 | View |
56399 | 8854 | CVE-2004-0426 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:967 | View |
56400 | 8854 | CVE-2004-0426 | XF:rsync-write-files(16014) | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
62772 | JVNDB-2004-000113 | Linux Kernel の do_fork() 関数におけるメモリリークによるサービス運用妨害 (DoS) の脆弱性 | Linux Kernel に実装されている do_fork() 関数には、子プロセスを生成する際にメモリを割り当てた後にエラーが生じた場合、正しくメモリの解放を行わなず、管理情報も修正しない複数の脆弱性が存在します。 | CVE-2004-0427 | 8854 | 2.1 | http://jvndb.jvn.jp/ja/contents/2004/JVNDB-2004-000113.html | View |