Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2017-17434

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

rsync是澳大利亚软件开发者安德鲁-垂鸠(Andrew Tridgell)和保罗-麦可拉斯(Paul Mackerras)共同研发的一套用于类Unix系统中的数据镜像备份应用程序,它能够同步更新两处计算机的文件与目录,并利用差分编码减少数据传输。 rsync 2017-11-03之前的3.1.2和3.1.3-development版本中的守护进程存在安全漏洞,该漏洞源于程序没有检测daemon_filter_list数据结构中的fnamecmp文件名,并未对‘xname follows’字符串中的路径名

AI Predicted 7.5 Difficulty: Easy EPSS 3.36% · P88
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2017-17434

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
The daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, does not check for fnamecmp filenames in the daemon_filter_list data structure (in the recv_files function in receiver.c) and also does not apply the sanitize_paths protection mechanism to pathnames found in "xname follows" strings (in the read_ndx_and_attrs function in rsync.c), which allows remote attackers to bypass intended access restrictions.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
rsync 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
rsync是澳大利亚软件开发者安德鲁-垂鸠(Andrew Tridgell)和保罗-麦可拉斯(Paul Mackerras)共同研发的一套用于类Unix系统中的数据镜像备份应用程序,它能够同步更新两处计算机的文件与目录,并利用差分编码减少数据传输。 rsync 2017-11-03之前的3.1.2和3.1.3-development版本中的守护进程存在安全漏洞,该漏洞源于程序没有检测daemon_filter_list数据结构中的fnamecmp文件名,并未对‘xname follows’字符串中的路径名
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2017-17434

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2017-17434

登录查看更多情报信息。

Vendor Advisories for CVE-2017-17434 (1)

Mailing List Discussions for CVE-2017-17434 (1)

Other References for CVE-2017-17434 (3)

Same Patch Batch · n/a · 2017-12-06 · 13 CVEs total

CVE-2017-17068 Auth0 auth0.js library 安全漏洞
CVE-2017-17446 Game_Music_Emu library 安全漏洞
CVE-2017-17440 GNU Libextractor 安全漏洞
CVE-2017-16884 MistServer 跨站脚本漏洞
CVE-2017-17055 Artica Web Proxy 跨站脚本漏洞
CVE-2017-17381 QEMU 安全漏洞
CVE-2017-17439 Heimdal 安全漏洞
CVE-2017-17069 Amazon Audible for Windows 安全漏洞
CVE-2017-17383 CloudBees Jenkins 跨站脚本漏洞
CVE-2017-17433 rsync 安全漏洞
CVE-2017-14374 Dell Storage Manager 安全漏洞
CVE-2017-17432 OpenAFS 安全漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2017-17434

No comments yet


Leave a comment