Unrated severityNVD Advisory· Published Dec 1, 2007· Updated Apr 23, 2026
CVE-2007-6199
CVE-2007-6199
Description
rsync before 3.0.0pre6, when running a writable rsync daemon that is not using chroot, allows remote attackers to access restricted files via unknown vectors that cause rsync to create a symlink that points outside of the module's hierarchy.
Affected products
32cpe:2.3:a:rsync:rsync:2.3.1:*:*:*:*:*:*:*+ 31 more
- cpe:2.3:a:rsync:rsync:2.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:rsync:rsync:2.3.2:*:*:*:*:*:*:*
- cpe:2.3:a:rsync:rsync:2.3.2_1.2alpha:*:*:*:*:*:*:*
- cpe:2.3:a:rsync:rsync:2.3.2_1.2arm:*:*:*:*:*:*:*
- cpe:2.3:a:rsync:rsync:2.3.2_1.2intel:*:*:*:*:*:*:*
- cpe:2.3:a:rsync:rsync:2.3.2_1.2m68k:*:*:*:*:*:*:*
- cpe:2.3:a:rsync:rsync:2.3.2_1.2ppc:*:*:*:*:*:*:*
- cpe:2.3:a:rsync:rsync:2.3.2_1.2sparc:*:*:*:*:*:*:*
- cpe:2.3:a:rsync:rsync:2.3.2_1.3:*:*:*:*:*:*:*
- cpe:2.3:a:rsync:rsync:2.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:rsync:rsync:2.4.1:*:*:*:*:*:*:*
- cpe:2.3:a:rsync:rsync:2.4.3:*:*:*:*:*:*:*
- cpe:2.3:a:rsync:rsync:2.4.4:*:*:*:*:*:*:*
- cpe:2.3:a:rsync:rsync:2.4.5:*:*:*:*:*:*:*
- cpe:2.3:a:rsync:rsync:2.4.6:*:*:*:*:*:*:*
- cpe:2.3:a:rsync:rsync:2.4.8:*:*:*:*:*:*:*
- cpe:2.3:a:rsync:rsync:2.5.0:*:*:*:*:*:*:*
- cpe:2.3:a:rsync:rsync:2.5.1:*:*:*:*:*:*:*
- cpe:2.3:a:rsync:rsync:2.5.2:*:*:*:*:*:*:*
- cpe:2.3:a:rsync:rsync:2.5.3:*:*:*:*:*:*:*
- cpe:2.3:a:rsync:rsync:2.5.4:*:*:*:*:*:*:*
- cpe:2.3:a:rsync:rsync:2.5.5:*:*:*:*:*:*:*
- cpe:2.3:a:rsync:rsync:2.5.6:*:*:*:*:*:*:*
- cpe:2.3:a:rsync:rsync:2.5.7:*:*:*:*:*:*:*
- cpe:2.3:a:rsync:rsync:2.6:*:*:*:*:*:*:*
- cpe:2.3:a:rsync:rsync:2.6.1:*:*:*:*:*:*:*
- cpe:2.3:a:rsync:rsync:2.6.2:*:*:*:*:*:*:*
- cpe:2.3:a:rsync:rsync:2.6.5:*:*:*:*:*:*:*
- cpe:2.3:a:rsync:rsync:2.6.6:*:*:*:*:*:*:*
- cpe:2.3:a:rsync:rsync:2.6.7:*:*:*:*:*:*:*
- cpe:2.3:a:rsync:rsync:2.6.8:*:*:*:*:*:*:*
- cpe:2.3:a:rsync:rsync:2.6.9:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
17- www.securityfocus.com/bid/26638nvdPatch
- secunia.com/advisories/27863nvdVendor Advisory
- lists.apple.com/archives/security-announce//2008/Jul/msg00003.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2008-01/msg00002.htmlnvd
- rsync.samba.org/security.htmlnvd
- secunia.com/advisories/27853nvd
- secunia.com/advisories/28412nvd
- secunia.com/advisories/28457nvd
- secunia.com/advisories/31326nvd
- secunia.com/advisories/61005nvd
- securitytracker.com/idnvd
- support.f5.com/kb/en-us/solutions/public/15000/500/sol15549.htmlnvd
- wiki.rpath.com/wiki/Advisories:rPSA-2007-0257nvd
- www.mandriva.com/en/security/advisoriesnvd
- www.securityfocus.com/archive/1/487991/100/0/threadednvd
- www.vupen.com/english/advisories/2007/4057nvd
- www.vupen.com/english/advisories/2008/2268nvd
News mentions
0No linked articles in our index yet.