← All CVEs

CVE-2003-0962

high · 7.5

Heap-based buffer overflow in rsync before 2.5.7, when running in server mode, allows remote attackers to execute arbitrary code and possibly escape the chroot jail.

7.5
CVSS
21.2%
EPSS (exploit prob.)
97th
EPSS percentile
2003-12-15
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

VendorProductAffected versions
andrew_tridgellrsync2.3.1
andrew_tridgellrsync2.3.2
andrew_tridgellrsync2.4.0
andrew_tridgellrsync2.4.1
andrew_tridgellrsync2.4.3
andrew_tridgellrsync2.4.4
andrew_tridgellrsync2.4.5
andrew_tridgellrsync2.4.6
andrew_tridgellrsync2.4.8
andrew_tridgellrsync2.5.0
andrew_tridgellrsync2.5.1
andrew_tridgellrsync2.5.2
andrew_tridgellrsync2.5.3
andrew_tridgellrsync2.5.4
andrew_tridgellrsync2.5.5
andrew_tridgellrsync2.5.6
redhatrsync2.4.6-2
redhatrsync2.4.6-5
redhatrsync2.4.6-5
redhatrsync2.5.4-2
redhatrsync2.5.5-1
redhatrsync2.5.5-4
engardelinuxsecure_community1.0.1
engardelinuxsecure_community2.0
engardelinuxsecure_linux1.1
engardelinuxsecure_linux1.2
engardelinuxsecure_linux1.5
slackwareslackware_linux8.1
slackwareslackware_linux9.0
slackwareslackware_linux9.1
slackwareslackware_linuxcurrent

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2003-0962