Back

CVE-2004-0792

Directory traversal vulnerability in the sanitize_path function in util.c for rsync 2.6.2 and earlier, when chroot is disabled, allows attackers to read or write certain files.

Published: Oct 20, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (27)

Vendor Product Version
andrew_tridgell rsync 2.3.1
andrew_tridgell rsync 2.3.2
andrew_tridgell rsync 2.3.2_1.2
andrew_tridgell rsync 2.3.2_1.2
andrew_tridgell rsync 2.3.2_1.2
andrew_tridgell rsync 2.3.2_1.2
andrew_tridgell rsync 2.3.2_1.2
andrew_tridgell rsync 2.3.2_1.2
andrew_tridgell rsync 2.3.2_1.3
andrew_tridgell rsync 2.4.0
andrew_tridgell rsync 2.4.1
andrew_tridgell rsync 2.4.3
andrew_tridgell rsync 2.4.4
andrew_tridgell rsync 2.4.5
andrew_tridgell rsync 2.4.6
andrew_tridgell rsync 2.4.8
andrew_tridgell rsync 2.5.0
andrew_tridgell rsync 2.5.1
andrew_tridgell rsync 2.5.2
andrew_tridgell rsync 2.5.3

…and 7 more

GitHub Security Advisory GHSA-6v45-fh9q-v72q

Directory traversal vulnerability in the sanitize_path function in util.c for rsync 2.6.2 and...

Risk Scores

CVSS Score 6.4 / 10
EPSS Score 2.32%

Top 18% most likely to be exploited

Threat Score 26.3 / 100

Data Sources

NVD EPSS GitHub