CVE-2007-4091

Impact:
Moderate
Public Date:
2007-08-15
CWE:
CWE-193
Bugzilla:
252394: CVE-2007-4091 rsync off by one flaw

The MITRE CVE dictionary describes this issue as:

Multiple off-by-one errors in the sender.c in rsync 2.6.9 might allow remote attackers to execute arbitrary code via directory names that are not properly handled when calling the f_name function.

Find out more about CVE-2007-4091 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

Not vulnerable. This flaw did not affect Red Hat Enterprise Linux 2.1, 3, or 4 due to the version of rsync.

This flaw does exist in Red Hat Enterprise Linux 5, but due to the nature of the flaw it is not exploitable with any security consequence due to stack-protector.

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.