CVE-2003-0962
 
Severity Score
7.5
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Heap-based buffer overflow in rsync before 2.5.7, when running in server mode, allows remote attackers to execute arbitrary code and possibly escape the chroot jail.
Desbordamiento de búfer en el montón en rsync anteriores a 2.5.7, cuando se ejecuta en modo servidor, permite a atacantes remotos ejecutar código arbitrario y posiblemente escapar del confinamiento chroot.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2003-11-26 CVE Reserved
- 2003-12-10 CVE Published
- 2024-08-08 CVE Updated
- 2024-10-07 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (29)
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.redhat.com/support/errata/RHSA-2003-398.html | 2018-05-03 | |
http://www.securityfocus.com/bid/9153 | 2018-05-03 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Andrew Tridgell Search vendor "Andrew Tridgell" | Rsync Search vendor "Andrew Tridgell" for product "Rsync" | 2.3.1 Search vendor "Andrew Tridgell" for product "Rsync" and version "2.3.1" | - |
Affected
| ||||||
Andrew Tridgell Search vendor "Andrew Tridgell" | Rsync Search vendor "Andrew Tridgell" for product "Rsync" | 2.3.2 Search vendor "Andrew Tridgell" for product "Rsync" and version "2.3.2" | - |
Affected
| ||||||
Andrew Tridgell Search vendor "Andrew Tridgell" | Rsync Search vendor "Andrew Tridgell" for product "Rsync" | 2.4.0 Search vendor "Andrew Tridgell" for product "Rsync" and version "2.4.0" | - |
Affected
| ||||||
Andrew Tridgell Search vendor "Andrew Tridgell" | Rsync Search vendor "Andrew Tridgell" for product "Rsync" | 2.4.1 Search vendor "Andrew Tridgell" for product "Rsync" and version "2.4.1" | - |
Affected
| ||||||
Andrew Tridgell Search vendor "Andrew Tridgell" | Rsync Search vendor "Andrew Tridgell" for product "Rsync" | 2.4.3 Search vendor "Andrew Tridgell" for product "Rsync" and version "2.4.3" | - |
Affected
| ||||||
Andrew Tridgell Search vendor "Andrew Tridgell" | Rsync Search vendor "Andrew Tridgell" for product "Rsync" | 2.4.4 Search vendor "Andrew Tridgell" for product "Rsync" and version "2.4.4" | - |
Affected
| ||||||
Andrew Tridgell Search vendor "Andrew Tridgell" | Rsync Search vendor "Andrew Tridgell" for product "Rsync" | 2.4.5 Search vendor "Andrew Tridgell" for product "Rsync" and version "2.4.5" | - |
Affected
| ||||||
Andrew Tridgell Search vendor "Andrew Tridgell" | Rsync Search vendor "Andrew Tridgell" for product "Rsync" | 2.4.6 Search vendor "Andrew Tridgell" for product "Rsync" and version "2.4.6" | - |
Affected
| ||||||
Andrew Tridgell Search vendor "Andrew Tridgell" | Rsync Search vendor "Andrew Tridgell" for product "Rsync" | 2.4.8 Search vendor "Andrew Tridgell" for product "Rsync" and version "2.4.8" | - |
Affected
| ||||||
Andrew Tridgell Search vendor "Andrew Tridgell" | Rsync Search vendor "Andrew Tridgell" for product "Rsync" | 2.5.0 Search vendor "Andrew Tridgell" for product "Rsync" and version "2.5.0" | - |
Affected
| ||||||
Andrew Tridgell Search vendor "Andrew Tridgell" | Rsync Search vendor "Andrew Tridgell" for product "Rsync" | 2.5.1 Search vendor "Andrew Tridgell" for product "Rsync" and version "2.5.1" | - |
Affected
| ||||||
Andrew Tridgell Search vendor "Andrew Tridgell" | Rsync Search vendor "Andrew Tridgell" for product "Rsync" | 2.5.2 Search vendor "Andrew Tridgell" for product "Rsync" and version "2.5.2" | - |
Affected
| ||||||
Andrew Tridgell Search vendor "Andrew Tridgell" | Rsync Search vendor "Andrew Tridgell" for product "Rsync" | 2.5.3 Search vendor "Andrew Tridgell" for product "Rsync" and version "2.5.3" | - |
Affected
| ||||||
Andrew Tridgell Search vendor "Andrew Tridgell" | Rsync Search vendor "Andrew Tridgell" for product "Rsync" | 2.5.4 Search vendor "Andrew Tridgell" for product "Rsync" and version "2.5.4" | - |
Affected
| ||||||
Andrew Tridgell Search vendor "Andrew Tridgell" | Rsync Search vendor "Andrew Tridgell" for product "Rsync" | 2.5.5 Search vendor "Andrew Tridgell" for product "Rsync" and version "2.5.5" | - |
Affected
| ||||||
Andrew Tridgell Search vendor "Andrew Tridgell" | Rsync Search vendor "Andrew Tridgell" for product "Rsync" | 2.5.6 Search vendor "Andrew Tridgell" for product "Rsync" and version "2.5.6" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Rsync Search vendor "Redhat" for product "Rsync" | 2.4.6-2 Search vendor "Redhat" for product "Rsync" and version "2.4.6-2" | i386 |
Affected
| ||||||
Redhat Search vendor "Redhat" | Rsync Search vendor "Redhat" for product "Rsync" | 2.4.6-5 Search vendor "Redhat" for product "Rsync" and version "2.4.6-5" | i386 |
Affected
| ||||||
Redhat Search vendor "Redhat" | Rsync Search vendor "Redhat" for product "Rsync" | 2.4.6-5 Search vendor "Redhat" for product "Rsync" and version "2.4.6-5" | ia64 |
Affected
| ||||||
Redhat Search vendor "Redhat" | Rsync Search vendor "Redhat" for product "Rsync" | 2.5.4-2 Search vendor "Redhat" for product "Rsync" and version "2.5.4-2" | i386 |
Affected
| ||||||
Redhat Search vendor "Redhat" | Rsync Search vendor "Redhat" for product "Rsync" | 2.5.5-1 Search vendor "Redhat" for product "Rsync" and version "2.5.5-1" | i386 |
Affected
| ||||||
Redhat Search vendor "Redhat" | Rsync Search vendor "Redhat" for product "Rsync" | 2.5.5-4 Search vendor "Redhat" for product "Rsync" and version "2.5.5-4" | i386 |
Affected
| ||||||
Engardelinux Search vendor "Engardelinux" | Secure Community Search vendor "Engardelinux" for product "Secure Community" | 1.0.1 Search vendor "Engardelinux" for product "Secure Community" and version "1.0.1" | - |
Affected
| ||||||
Engardelinux Search vendor "Engardelinux" | Secure Community Search vendor "Engardelinux" for product "Secure Community" | 2.0 Search vendor "Engardelinux" for product "Secure Community" and version "2.0" | - |
Affected
| ||||||
Engardelinux Search vendor "Engardelinux" | Secure Linux Search vendor "Engardelinux" for product "Secure Linux" | 1.1 Search vendor "Engardelinux" for product "Secure Linux" and version "1.1" | professional |
Affected
| ||||||
Engardelinux Search vendor "Engardelinux" | Secure Linux Search vendor "Engardelinux" for product "Secure Linux" | 1.2 Search vendor "Engardelinux" for product "Secure Linux" and version "1.2" | professional |
Affected
| ||||||
Engardelinux Search vendor "Engardelinux" | Secure Linux Search vendor "Engardelinux" for product "Secure Linux" | 1.5 Search vendor "Engardelinux" for product "Secure Linux" and version "1.5" | professional |
Affected
| ||||||
Slackware Search vendor "Slackware" | Slackware Linux Search vendor "Slackware" for product "Slackware Linux" | 8.1 Search vendor "Slackware" for product "Slackware Linux" and version "8.1" | - |
Affected
| ||||||
Slackware Search vendor "Slackware" | Slackware Linux Search vendor "Slackware" for product "Slackware Linux" | 9.0 Search vendor "Slackware" for product "Slackware Linux" and version "9.0" | - |
Affected
| ||||||
Slackware Search vendor "Slackware" | Slackware Linux Search vendor "Slackware" for product "Slackware Linux" | 9.1 Search vendor "Slackware" for product "Slackware Linux" and version "9.1" | - |
Affected
| ||||||
Slackware Search vendor "Slackware" | Slackware Linux Search vendor "Slackware" for product "Slackware Linux" | current Search vendor "Slackware" for product "Slackware Linux" and version "current" | - |
Affected
|