CVE-2007-6199

rsync before 3.0.0pre6, when running a writable rsync daemon that is not using chroot, allows remote attackers to access restricted files via unknown vectors that cause rsync to create a symlink that points outside of the module’s hierarchy.

Date published : 2007-11-30

http://lists.apple.com/archives/security-announce//2008/Jul/msg00003.html

http://www.securityfocus.com/bid/26638