Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2004-2093

Buffer overflow in the open_socket_out function in socket.c for rsync 2.5.7 and earlier allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long RSYNC_PROXY environment variable. NOTE: since rsync is not setuid, this issue does not provide any additional privileges beyond those that are already available to the user. Therefore this issue may be REJECTED in the future.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 52.0%
CVSS Severity
CVSS v2 Score 4.6
Products affected by CVE-2004-2093
  • Gnu » Rsync » Version: N/A
    cpe:2.3:a:gnu:rsync:-
  • Gnu » Rsync » Version: 2.5.7
    cpe:2.3:a:gnu:rsync:2.5.7


Contact Us

Shodan ® - All rights reserved