← Vulnerability feed

Vulnerability record · CVE-2003-0962 · published 15 December 2003

CVE-2003-0962: Andrew tridgell rsync vulnerability

AAndrew Tridgell · Rsync

Heap-based buffer overflow in rsync before 2.5.7, when running in server mode, allows remote attackers to execute arbitrary code and possibly escape the chroot jail.

7.5 CVSS 2.0 High EPSS 21% · top 2.5%
7.5CVSS 2.0 base score
21%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
54References
16 Jun 2026Last modified by NVD

Description

Heap-based buffer overflow in rsync before 2.5.7, when running in server mode, allows remote attackers to execute arbitrary code and possibly escape the chroot jail.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
ftp://patches.sgi.com/support/free/security/advisories/20031202-01-U
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000794
http://marc.info/?l=bugtraq&m=107055681311602&w=2
http://marc.info/?l=bugtraq&m=107055684711629&w=2
http://marc.info/?l=bugtraq&m=107055702911867&w=2
http://marc.info/?l=bugtraq&m=107056923528423&w=2
http://secunia.com/advisories/10353
http://secunia.com/advisories/10354
http://secunia.com/advisories/10355
http://secunia.com/advisories/10356
http://secunia.com/advisories/10357
http://secunia.com/advisories/10358
http://secunia.com/advisories/10359
http://secunia.com/advisories/10360
http://secunia.com/advisories/10361
http://secunia.com/advisories/10362
http://secunia.com/advisories/10363
http://secunia.com/advisories/10364
http://secunia.com/advisories/10378
http://secunia.com/advisories/10474
http://www.kb.cert.org/vuls/id/325603 US Government Resource
http://www.mandriva.com/security/advisories?name=MDKSA-2003:111
http://www.osvdb.org/2898
http://www.redhat.com/support/errata/RHSA-2003-398.html PatchVendor Advisory
http://www.securityfocus.com/bid/9153 PatchVendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/13899
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9415
ftp://patches.sgi.com/support/free/security/advisories/20031202-01-U
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000794
http://marc.info/?l=bugtraq&m=107055681311602&w=2
http://marc.info/?l=bugtraq&m=107055684711629&w=2
http://marc.info/?l=bugtraq&m=107055702911867&w=2
http://marc.info/?l=bugtraq&m=107056923528423&w=2
http://secunia.com/advisories/10353
http://secunia.com/advisories/10354
http://secunia.com/advisories/10355
http://secunia.com/advisories/10356
http://secunia.com/advisories/10357
http://secunia.com/advisories/10358
http://secunia.com/advisories/10359

Track CVE-2003-0962 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2006-6235Gnu privacy guard vulnerabilityA "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute arbitrary c…EPSS 5.9%10.0CVE-2005-3625Easy software products cups vulnerabilityXpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of servic…EPSS 3.8%10.0CVE-2004-0891Rob flynn gaim vulnerabilityBuffer overflow in the MSN protocol handler for gaim 0.79 to 1.0.1 allows remote attackers to cause a denial of service (application crash) and possi…EPSS 6.9%10.0CVE-2004-0226Midnight commander vulnerabilityMultiple buffer overflows in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code.EPSS 3.9%10.0CVE-2002-0048Andrew tridgell rsync vulnerabilityMultiple signedness errors (mixed signed and unsigned numbers) in the I/O functions of rsync 2.4.6, 2.3.2, and other versions allow remote attackers …EPSS 34%10.0CVE-2001-1240Engardelinux secure linux vulnerabilityThe default configuration of sudo in Engarde Secure Linux 1.0.1 allows any user in the admin group to run certain commands that could be leveraged to…EPSS 1.8%10.0CVE-2000-0844Caldera openlinux ebuilder permissions and access controls vulnerabilitySome functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to exec…EPSS 16%10.0CVE-1999-0368Proftpd project proftpd vulnerabilityBuffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto.EPSS 40%

Source: NIST National Vulnerability Database (record CVE-2003-0962), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.