Red Hat Bugzilla – Bug 1522874
CVE-2017-17433 rsync: recv_files function metadata handling allows for access restriction bypass
Last modified: 2018-01-18 06:32:00 EST
The recv_files function in receiver.c in the daemon in rsync 3.1.2, and 3.1.3-development before 2017-11-03, proceeds with certain file metadata updates before checking for a filename in the daemon_filter_list data structure, which allows remote attackers to bypass intended access restrictions. Upstream patch: https://git.samba.org/?p=rsync.git;a=commit;h=3e06d40029cfdce9d0f73d87cfd4edaf54be9c51
Created rsync tracking bugs for this issue: Affects: fedora-all [bug 1511414]
Statement: Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.