CVE-2017-17434: Critical severity Samba rsync vulnerability
The daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, does not check for fnamecmp filenames in the daemonfilterlist data structure (in the recvfiles function in receiver.c) and also does not apply the sanitizepaths protection mechanism to pathnames found in "xname follows" strings (in the readndxandattrs function in rsync.c), which allows remote attackers to bypass intended access restrictions.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-17434?
The severity of CVE-2017-17434 is critical with a CVSS score of 9.8.
What software is affected by CVE-2017-17434?
The affected software includes rsync versions 3.1.2 and 3.1.3-development before 2017-12-03.
How can I mitigate the vulnerability in CVE-2017-17434?
To mitigate the vulnerability in CVE-2017-17434, update rsync to the latest version (3.1.3-6 or 3.2.7-1) provided by your distribution or vendor.
Where can I find more information about CVE-2017-17434?
You can find more information about CVE-2017-17434 in the references section of the vulnerability report.