Rsync path Spoofing Vulnerability
Release date:
Updated on:
Affected Systems:
Samba rsync 3.1.1
Description:
CVE (CAN) ID: CVE-2014-9512
Rsync is a fast incremental file transfer tool used for internal backup on the same host.
Rsync 3.1.1 has the path spoofing vulnerability. By launching a symbolic link attack on files in the synchronization path, remote attackers can exploit this vulnerability to write arbitrary files.
<* Source: vendor
*>
Suggestion:
Vendor patch:
Rsync
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://bugzilla.samba.org/show_bug.cgi? Id = 10977
Rsync + inotify implement real-time synchronization and backup of Git data
Rsync for file backup Synchronization
Rsync synchronizes two servers
Remote synchronization of Rsync in CentOS 6.5
Use Rsync in Ubuntu Linux for data backup and Synchronization
Linux uses the Rsync client to synchronize directories with the server for backup
Rsync details: click here
Rsync: click here
This article permanently updates the link address: