VDB
CVE-2003-0962
CVE-2003-0962
PUBLISHED
CVSS 7.5 HIGH
Heap-based buffer overflow in rsync before 2.5.7, when running in server mode, allows remote attackers to execute arbitrary code and possibly escape the chroot jail.
EPSS 21.16% · 97.5th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
21.16%
97.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| engardelinux | secure_linux | 1.1, 1.5, 1.2 |
| redhat | rsync | 2.4.6-5, 2.4.6-5, 2.5.4-2 |
| andrew_tridgell | rsync | 2.5.6, 2.5.1, 2.5.2 |
| n/a | n/a | n/a |
| engardelinux | secure_community | 2.0, 1.0.1 |
| slackware | slackware_linux | 9.0, 8.1, 9.1 |
Timeline
- CVE Published
- Sep 23, 2010 PoC Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Oct 31, 2023 EPSS Score
References
- 10362 third-party-advisory
- 10354 third-party-advisory
- 10353 third-party-advisory
- 10357 third-party-advisory
- 10474 third-party-advisory
- MDKSA-2003:111 vendor-advisory
- 9153 vdb
- 20031204 rsync security advisory (fwd) mailing-list
- 20031204 GLSA: exploitable heap overflow in rsync (200312-03) mailing-list
- oval:org.mitre.oval:def:9415 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2003-0962 advisory
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000794 url
- http://marc.info/?l=bugtraq&m=107055702911867&w=2 url
- http://secunia.com/advisories/10355 url
- http://secunia.com/advisories/10361 url
- http://secunia.com/advisories/10363 url
- http://secunia.com/advisories/10378 url
- http://www.redhat.com/support/errata/RHSA-2003-398.html url
- ftp://patches.sgi.com/support/free/security/advisories/20031202-01-U technical
- http://marc.info/?l=bugtraq&m=107055684711629&w=2 technical
…and 8 more