CVE-2007-6199: Critical severity Slackware Slackware Linux vulnerability
rsync before 3.0.0pre6, when running a writable rsync daemon that is not using chroot, allows remote attackers to access restricted files via unknown vectors that cause rsync to create a symlink that points outside of the module's hierarchy.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-6199?
CVE-2007-6199 has a moderate severity rating due to its potential to allow remote access to restricted files.
How do I fix CVE-2007-6199?
To fix CVE-2007-6199, upgrade rsync to version 3.0.0pre6 or later and ensure the rsync daemon is running with a chroot environment.
What systems are affected by CVE-2007-6199?
CVE-2007-6199 affects rsync versions before 3.0.0pre6 on various Linux distributions including Slackware.
What type of attack does CVE-2007-6199 facilitate?
CVE-2007-6199 facilitates attacks that exploit the ability to create symbolic links, potentially allowing unauthorized file access.
Is CVE-2007-6199 still a concern today?
While CVE-2007-6199 pertains to older versions of rsync, environments using outdated software may still be vulnerable.