CVE-2014-9512

rsync 3.1.1 - Arbitrary File Write via Symlink Attack

Title source: llm
STIX 2.1

Description

rsync 3.1.1 allows remote attackers to write to arbitrary files via a symlink attack on a file in the synchronization path.

References (15)

Core 15
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1034786
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/76093
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201605-04
Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2016-06/msg00112.html
Mailing List vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2016-06/msg00095.html
Exploit, Issue Tracking x_refsource_confirm
https://bugzilla.samba.org/show_bug.cgi?id=10977
Exploit x_refsource_misc
http://xteam.baidu.com/?p=169
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2879-1
Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2015-02/msg00041.html
Vendor Advisory x_refsource_confirm
https://support.apple.com/kb/HT211168
Vendor Advisory x_refsource_confirm
https://support.apple.com/kb/HT211170
Vendor Advisory x_refsource_confirm
https://support.apple.com/kb/HT211175
Vendor Advisory x_refsource_confirm
https://support.apple.com/kb/HT211171
Vendor Advisory x_refsource_confirm
https://support.apple.com/kb/HT211289

Scores

EPSS 0.0888
EPSS Percentile 92.7%

Details

CWE
CWE-59
Status published
Products (5)
opensuse/opensuse 13.1
opensuse/opensuse 13.2
oracle/solaris 10.0
oracle/solaris 11.3
samba/rsync 3.1.1
Published Feb 12, 2015
Tracked Since Feb 18, 2026