First published: Thu Dec 05 2024(Updated: )
rsync --safe-links options fail to verify whether a symbolic link destination contains another symbolic link with it leading to a path traversal vulnerability
Affected Software | Affected Version | How to fix |
---|---|---|
Samba |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2330676 is categorized as high due to the potential for path traversal exploitation.
To fix REDHAT-BUG-2330676, it is recommended to update to the latest version of rsync that addresses this vulnerability.
REDHAT-BUG-2330676 affects systems using the Samba version of rsync.
The vulnerability in REDHAT-BUG-2330676 is caused by the failure of the --safe-links option to verify symbolic link destinations properly.
Yes, REDHAT-BUG-2330676 can potentially lead to unauthorized access via path traversal attacks.