| Description: | The remote host is missing updates announced in advisory RHSA-2004:192.
Rsync is a program for synchronizing files over a network.
Rsync before 2.6.1 does not properly sanitize paths when running a read/write daemon without using chroot. This could allow a remote attacker to write files outside of the module's path, depending on the privileges assigned to the rsync daemon. Users not running an rsync daemon, running a read-only daemon, or running a chrooted daemon are not affected by this issue. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2004-0426 to this issue.
Users of Rsync are advised to upgrade to this updated package, which contains a backported patch and is not affected by this issue.
Solution: Please note that this update is available via Red Hat Network. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date
http://rhn.redhat.com/errata/RHSA-2004-192.html http://rsync.samba.org/#security_apr04
Risk factor : Medium |