Your submission was sent successfully! Close

CVE-2007-4091

Published: 16 August 2007

Multiple off-by-one errors in the sender.c in rsync 2.6.9 might allow remote attackers to execute arbitrary code via directory names that are not properly handled when calling the f_name function.

Priority

Unknown

Status

Package Release Status
rsync
Launchpad, Ubuntu, Debian
dapper
Released (2.6.6-1ubuntu2.1)
edgy
Released (2.6.8-2ubuntu3.1)
feisty
Released (2.6.9-3ubuntu1.1)
upstream Needs triage