REDHAT-BUG-2330676: Path Traversal
Published Dec 5, 2024
·Updated
rsync --safe-links options fail to verify whether a symbolic link destination contains another symbolic link with it leading to a path traversal vulnerability
Affected Software
1 affected component
samba rsync
Event History
Dec 5, 2024
Data Sourced
via Red Hat·09:59 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2330676?
The severity of REDHAT-BUG-2330676 is categorized as high due to the potential for path traversal exploitation.
2
How do I fix REDHAT-BUG-2330676?
To fix REDHAT-BUG-2330676, it is recommended to update to the latest version of rsync that addresses this vulnerability.
3
What types of systems are affected by REDHAT-BUG-2330676?
REDHAT-BUG-2330676 affects systems using the Samba version of rsync.
4
What is the cause of the vulnerability in REDHAT-BUG-2330676?
The vulnerability in REDHAT-BUG-2330676 is caused by the failure of the --safe-links option to verify symbolic link destinations properly.
5
Can REDHAT-BUG-2330676 lead to unauthorized access?
Yes, REDHAT-BUG-2330676 can potentially lead to unauthorized access via path traversal attacks.