CVE-2003-0962
high · 7.5Heap-based buffer overflow in rsync before 2.5.7, when running in server mode, allows remote attackers to execute arbitrary code and possibly escape the chroot jail.
7.5
CVSS
21.2%
EPSS (exploit prob.)
97th
EPSS percentile
2003-12-15
Published
AV:N/AC:L/Au:N/C:P/I:P/A:P
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| andrew_tridgell | rsync | 2.3.1 |
| andrew_tridgell | rsync | 2.3.2 |
| andrew_tridgell | rsync | 2.4.0 |
| andrew_tridgell | rsync | 2.4.1 |
| andrew_tridgell | rsync | 2.4.3 |
| andrew_tridgell | rsync | 2.4.4 |
| andrew_tridgell | rsync | 2.4.5 |
| andrew_tridgell | rsync | 2.4.6 |
| andrew_tridgell | rsync | 2.4.8 |
| andrew_tridgell | rsync | 2.5.0 |
| andrew_tridgell | rsync | 2.5.1 |
| andrew_tridgell | rsync | 2.5.2 |
| andrew_tridgell | rsync | 2.5.3 |
| andrew_tridgell | rsync | 2.5.4 |
| andrew_tridgell | rsync | 2.5.5 |
| andrew_tridgell | rsync | 2.5.6 |
| redhat | rsync | 2.4.6-2 |
| redhat | rsync | 2.4.6-5 |
| redhat | rsync | 2.4.6-5 |
| redhat | rsync | 2.5.4-2 |
| redhat | rsync | 2.5.5-1 |
| redhat | rsync | 2.5.5-4 |
| engardelinux | secure_community | 1.0.1 |
| engardelinux | secure_community | 2.0 |
| engardelinux | secure_linux | 1.1 |
| engardelinux | secure_linux | 1.2 |
| engardelinux | secure_linux | 1.5 |
| slackware | slackware_linux | 8.1 |
| slackware | slackware_linux | 9.0 |
| slackware | slackware_linux | 9.1 |
| slackware | slackware_linux | current |
Check a specific version with /api/v1/cve/match.
References
- ftp://patches.sgi.com/support/free/security/advisories/20031202-01-U
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000794
- http://marc.info/?l=bugtraq&m=107055681311602&w=2
- http://marc.info/?l=bugtraq&m=107055684711629&w=2
- http://marc.info/?l=bugtraq&m=107055702911867&w=2
- http://marc.info/?l=bugtraq&m=107056923528423&w=2
- http://secunia.com/advisories/10353
- http://secunia.com/advisories/10354
- http://secunia.com/advisories/10355
- http://secunia.com/advisories/10356
- http://secunia.com/advisories/10357
- http://secunia.com/advisories/10358
- http://secunia.com/advisories/10359
- http://secunia.com/advisories/10360
- http://secunia.com/advisories/10361
- http://secunia.com/advisories/10362
- http://secunia.com/advisories/10363
- http://secunia.com/advisories/10364
- http://secunia.com/advisories/10378
- http://secunia.com/advisories/10474
- http://www.kb.cert.org/vuls/id/325603
- http://www.mandriva.com/security/advisories?name=MDKSA-2003:111
- http://www.osvdb.org/2898
- http://www.redhat.com/support/errata/RHSA-2003-398.html
- http://www.securityfocus.com/bid/9153
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2003-0962