CVE-2007-4091

Publication date 16 August 2007

Last updated 24 July 2024


Ubuntu priority

Multiple off-by-one errors in the sender.c in rsync 2.6.9 might allow remote attackers to execute arbitrary code via directory names that are not properly handled when calling the f_name function.

Status

Package Ubuntu Release Status
rsync 7.04 feisty
Fixed 2.6.9-3ubuntu1.1
6.10 edgy
Fixed 2.6.8-2ubuntu3.1
6.06 LTS dapper
Fixed 2.6.6-1ubuntu2.1

References

Related Ubuntu Security Notices (USN)

    • USN-500-1
    • rsync vulnerability
    • 20 August 2007

Other references