Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 200821 - net-misc/rsync < 2.6.9-r5 Security bypass (CVE-2007-{6199,6200})
Summary: net-misc/rsync < 2.6.9-r5 Security bypass (CVE-2007-{6199,6200})
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL: http://secunia.com/advisories/27863/
Whiteboard: B4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2007-11-30 10:01 UTC by Lars Hartmann
Modified: 2020-04-04 08:31 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Lars Hartmann 2007-11-30 10:01:30 UTC
Two vulnerabilities have been reported in rsync, which can be exploited by malicious users to bypass certain security restrictions.

1) An error in the rsync daemon when the "use chroot" option is disabled can be exploited to gain access to files outside of the module's hierarchy via symlink attacks.

2) An error exists within the enforcing of the "exclude", "exclude from", and "filter" options. This can be exploited to bypass access restrictions and gain access to hidden files via e.g. symlink attacks, if the filename is known.

The vulnerabilities are reported in version 2.6.9. Prior versions may also be affected.

Solution: apply Vendor Patch:
http://rsync.samba.org/ftp/rsync/munge-symlinks-2.6.9.diff

Reproducible: Always
Comment 1 Lars Hartmann 2007-11-30 10:09:03 UTC
maintainers please advise and provide an updated ebuild
Comment 2 SpanKY gentoo-dev 2007-12-01 17:54:22 UTC
rsync-2.6.9-r5 in the tree with the fix from upstream
Comment 3 Robert Buchholz (RETIRED) gentoo-dev 2007-12-01 18:14:33 UTC
Arches, please test and mark stable net-misc/rsync-2.6.9-r5.
Target keywords : "alpha amd64 arm hppa ia64 m68k mips ppc ppc64 s390 sh sparc x86"
Comment 4 Markus Meier gentoo-dev 2007-12-01 19:33:49 UTC
x86 stable
Comment 5 Christoph Mende (RETIRED) gentoo-dev 2007-12-01 21:28:27 UTC
amd64 stable
Comment 6 Markus Ullmann (RETIRED) gentoo-dev 2007-12-01 22:38:18 UTC
Stable on arm/sparc
Comment 7 Jose Luis Rivero (yoswink) (RETIRED) gentoo-dev 2007-12-02 13:01:24 UTC
alpha tested and marked stable.
Comment 8 Tobias Scherbaum (RETIRED) gentoo-dev 2007-12-02 15:25:59 UTC
ppc stable
Comment 9 Markus Rothe (RETIRED) gentoo-dev 2007-12-02 18:47:23 UTC
ppc64 stable
Comment 10 Jeroen Roovers (RETIRED) gentoo-dev 2007-12-03 17:21:56 UTC
Stable for HPPA.
Comment 11 Raúl Porcel (RETIRED) gentoo-dev 2007-12-03 21:50:36 UTC
ia64 stable
Comment 12 Lars Hartmann 2007-12-04 07:29:29 UTC
this bug here is ready for glsa decision
Comment 13 Robert Buchholz (RETIRED) gentoo-dev 2007-12-05 02:13:59 UTC
Degrading to B4 since this only affects daemons that allow writing via rsync.

I tend to vote NO here because it affects what seems to me a marginal configuration.
Comment 14 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-12-05 08:42:27 UTC
voting NO too and closing.
Comment 15 Peter Volkov (RETIRED) gentoo-dev 2008-03-06 09:53:20 UTC
Does not affect current (2008.0) release. Removing release.