7.5

CVE-2024-12088

Rsync: --safe-links option bypass leads to path traversal

A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from the server contains another symbolic link within it. This results in a path traversal vulnerability, which may lead to arbitrary file write outside the desired directory.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Samba ≫ Rsync Version <= 3.3.0
Redhat ≫ Discovery Version 1.14
Redhat ≫ Enterprise Linux Version 6.0
Redhat ≫ Enterprise Linux Version 7.0
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Version 9.0
Redhat ≫ Enterprise Linux Version 10.0
Redhat ≫ Enterprise Linux Eus Version 9.6
Redhat ≫ Enterprise Linux For Arm 64 Version 8.0_aarch64
Redhat ≫ Enterprise Linux For Arm 64 Version 9.0_aarch64
Redhat ≫ Enterprise Linux For Arm 64 Eus Version 9.6_aarch64
Archlinux ≫ Arch Linux Version -
Gentoo ≫ Linux Version -
Nixos ≫ Nixos Version < 24.11
Novell ≫ Suse Linux Version -
Tritondatacenter ≫ Smartos Version < 20250123
Almalinux ≫ Almalinux Version 8.0 Update -
Almalinux ≫ Almalinux Version 9.0 Update -
Almalinux ≫ Almalinux Version 10.0 Update -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.75% 0.91
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
RedHat 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

https://kb.cert.org/vuls/id/952657
Third Party Advisory
https://github.com/google/security-research/security/advisories/GHSA-p5pg-x43v-mvqj
Third Party Advisory
https://access.redhat.com/security/cve/CVE-2024-12088
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2330676
Third Party Advisory
Issue Tracking
https://access.redhat.com/errata/RHSA-2025:2600
Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:7050
Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:8385
Third Party Advisory
https://access.redhat.com/errata/RHBA-2025:6470
https://security.netapp.com/advisory/ntap-20250131-0002/
https://lists.debian.org/debian-lts-announce/2025/01/msg00008.html
https://www.kb.cert.org/vuls/id/952657