CVE-2017-17433
- EPSS 1.56%
- Veröffentlicht 06.12.2017 03:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The recv_files function in receiver.c in the daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, proceeds with certain file metadata updates before checking for a filename in the daemon_filter_list data structure, which allows remote atta...
CVE-2017-16548
- EPSS 3.34%
- Veröffentlicht 06.11.2017 05:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The receive_xattr function in xattrs.c in rsync 3.1.2 and 3.1.3-development does not check for a trailing '\0' character in an xattr name, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) ...
CVE-2017-15994
- EPSS 0.13%
- Veröffentlicht 29.10.2017 06:29:01
- Zuletzt bearbeitet 13.05.2026 00:24:29
rsync 3.1.3-development before 2017-10-24 mishandles archaic checksums, which makes it easier for remote attackers to bypass intended access restrictions. NOTE: the rsync development branch has significant use beyond the rsync developers, e.g., the c...
CVE-2014-9512
- EPSS 8.88%
- Veröffentlicht 12.02.2015 16:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
rsync 3.1.1 allows remote attackers to write to arbitrary files via a symlink attack on a file in the synchronization path.
CVE-2014-2855
- EPSS 17.19%
- Veröffentlicht 23.04.2014 15:55:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
The check_secret function in authenticate.c in rsync 3.1.0 and earlier allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a user name which does not exist in the secrets file.
CVE-2011-1097
- EPSS 1.62%
- Veröffentlicht 30.03.2011 22:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
rsync 3.x before 3.0.8, when certain recursion, deletion, and ownership options are used, allows remote rsync servers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via malformed data.
CVE-2008-1720
- EPSS 8.44%
- Veröffentlicht 10.04.2008 19:05:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Buffer overflow in rsync 2.6.9 to 3.0.1, with extended attribute (xattr) support enabled, might allow remote attackers to execute arbitrary code via unknown vectors.
CVE-2002-0080
- EPSS 0.79%
- Veröffentlicht 15.03.2002 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
rsync, when running in daemon mode, does not properly call setgroups before dropping privileges, which could provide supplemental group privileges to local users, who could then read certain files that would otherwise be disallowed.