CVE-2017-17434
9.8
CRITICAL · CVSS 3.0 · EPSS 3.3% (pctl 88)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
The daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, does not check for fnamecmp filenames in the daemon_filter_list data structure (in the recv_files function in receiver.c) and also does not apply the sanitize_paths protection mechanism to pathnames found in "xname follows" strings (in the read_ndx_and_attrs function in rsync.c), which allows remote attackers to bypass intended access restrictions.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.27% — more likely to be exploited than 88% of all CVEs |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2017-12-06 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| debian | debian linux |
| samba | rsync |
References
- http://security.cucumberlinux.com/security/details.php?id=170
- https://git.samba.org/?p=rsync.git%3Ba=commit%3Bh=5509597decdbd7b91994210f700329d8a35e70a1
- https://git.samba.org/?p=rsync.git%3Ba=commit%3Bh=70aeb5fddd1b2f8e143276f8d5a085db16c593b9
- https://lists.debian.org/debian-lts-announce/2017/12/msg00020.html
- https://www.debian.org/security/2017/dsa-4068
- http://security.cucumberlinux.com/security/details.php?id=170
- https://git.samba.org/?p=rsync.git%3Ba=commit%3Bh=5509597decdbd7b91994210f700329d8a35e70a1
- https://git.samba.org/?p=rsync.git%3Ba=commit%3Bh=70aeb5fddd1b2f8e143276f8d5a085db16c593b9
- https://lists.debian.org/debian-lts-announce/2017/12/msg00020.html
- https://www.debian.org/security/2017/dsa-4068
→ the Explorer · watch your stack · NVD