VDB
CVE-2003-0962
CVE-2003-0962
PUBLISHED
CVSS 7.5 HIGH
Heap-based buffer overflow in rsync before 2.5.7, when running in server mode, allows remote attackers to execute arbitrary code and possibly escape the chroot jail.
EPSS 44.26% · 97.6th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
44.26%
97.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| engardelinux | secure_linux | 1.1, 1.5, 1.2 |
| redhat | rsync | 2.4.6-5, 2.4.6-5, 2.5.4-2 |
| andrew_tridgell | rsync | 2.5.6, 2.5.1, 2.5.2 |
| n/a | n/a | n/a |
| engardelinux | secure_community | 2.0, 1.0.1 |
| slackware | slackware_linux | 9.0, 8.1, 9.1 |
Timeline
- Dec 10, 2003 CVE Published
- Sep 23, 2010 PoC Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Oct 30, 2023 EPSS Score
References
- 20031204 rsync security advisory (fwd) mailing-list
- 2003-0048 vendor-advisory
- 10362 third-party-advisory
- 10364 third-party-advisory
- 10354 third-party-advisory
- linux-rsync-heap-overflow(13899) vdb
- 10363 third-party-advisory
- 10353 third-party-advisory
- 10357 third-party-advisory
- 10355 third-party-advisory
- VU#325603 third-party-advisory
- 10358 third-party-advisory
- 10378 third-party-advisory
- 20031204 GLSA: exploitable heap overflow in rsync (200312-03) mailing-list
- 10360 third-party-advisory
- 10361 third-party-advisory
- CLA-2003:794 vendor-advisory
- 20031204 [OpenPKG-SA-2003.051] OpenPKG Security Advisory (rsync) mailing-list
- 10474 third-party-advisory
- 20031202-01-U vendor-advisory
…and 8 more