CVE-2017-17433: Medium severity Debian Debian Linux vulnerability
The recvfiles function in receiver.c in the daemon in rsync 3.1.2, and 3.1.3-development before 2017-11-03, proceeds with certain file metadata updates before checking for a filename in the daemonfilterlist data structure, which allows remote attackers to bypass intended access restrictions.
Upstream patch:
https://git.samba.org/?p=rsync.git;a=commit;h=3e06d40029cfdce9d0f73d87cfd4edaf54be9c51
Other sources
The recvfiles function in receiver.c in the daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, proceeds with certain file metadata updates before checking for a filename in the daemonfilterlist data structure, which allows remote attackers to bypass intended access restrictions.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2017-17433?
CVE-2017-17433 is a vulnerability in the rsync daemon in versions 3.1.2 and 3.1.3-development before 2017-12-03 that allows remote attackers to bypass access restrictions.
How does CVE-2017-17433 affect rsync?
CVE-2017-17433 affects the recv_files function in receiver.c in the rsync daemon, allowing remote attackers to bypass intended access restrictions.
What is the severity of CVE-2017-17433?
The severity of CVE-2017-17433 is high, with a severity value of 3.7.
Which software versions are affected by CVE-2017-17433?
CVE-2017-17433 affects rsync versions 3.1.2 and 3.1.3-development before 2017-12-03.
How can I fix CVE-2017-17433?
To fix CVE-2017-17433, update rsync to version 3.1.3-6, 3.2.3-4+deb11u1, or 3.2.7-1, depending on your distribution.