Samba

Rsync

41 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.47%
  • Veröffentlicht 13.08.2026 14:38:10
  • Zuletzt bearbeitet 31.08.2026 15:38:58

rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated remote attackers to bypass IP-based access controls by sending a crafted PROXY protocol header with a forged source address. Attackers who can connect...

  • EPSS 0.31%
  • Veröffentlicht 13.08.2026 14:37:14
  • Zuletzt bearbeitet 31.08.2026 15:39:11

rsync before 3.5.0 contains an improper path handling vulnerability that allows a malicious sender to expand the scope of --delete operations beyond the intended destination subtree by sending a crafted file list that causes rsync to reclassify impli...

  • EPSS 0.28%
  • Veröffentlicht 13.08.2026 14:36:00
  • Zuletzt bearbeitet 31.08.2026 15:31:33

rsync before 3.5.0 contains a privilege confusion vulnerability in the name-converter subprocess uid/gid mapping that allows local attackers to cause transferred files to be owned by root by influencing name-converter responses to return empty values...

  • EPSS 0.27%
  • Veröffentlicht 13.08.2026 14:35:34
  • Zuletzt bearbeitet 31.08.2026 15:39:23

rsync before 3.5.0 contains a filter rule bypass vulnerability that allows authenticated clients to override module-level filter restrictions by supplying malicious --filter merge file directives. Attackers can inject client-side merge file directive...

  • EPSS 0.18%
  • Veröffentlicht 13.08.2026 14:34:22
  • Zuletzt bearbeitet 31.08.2026 15:39:32

rsync before 3.5.0 contains a path traversal vulnerability that allows remote clients to access files outside the intended module root when use chroot is disabled and the module root path or a component of it is a symlink. The daemon calls chdir() to...

  • EPSS 0.13%
  • Veröffentlicht 13.08.2026 14:33:18
  • Zuletzt bearbeitet 31.08.2026 15:12:57

rsync before 3.5.0 contains a symlink following vulnerability that allows local attackers to overwrite arbitrary files by placing a symlink at a predictable output path such as --log-file, --write-batch, or daemon-mode log and statistics paths. Attac...

  • EPSS 0.14%
  • Veröffentlicht 13.08.2026 14:32:26
  • Zuletzt bearbeitet 31.08.2026 15:26:06

rsync before 3.5.0 contains an arbitrary file read vulnerability that allows attackers to read files accessible to the rsync daemon process by exploiting symlink following in input configuration file handling including --files-from, --password-file, ...

  • EPSS 0.15%
  • Veröffentlicht 20.05.2026 13:16:17
  • Zuletzt bearbeitet 19.08.2026 12:17:41

Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended directories by replacing parent directory components with symbolic links...

  • EPSS 0.28%
  • Veröffentlicht 20.05.2026 00:52:38
  • Zuletzt bearbeitet 24.07.2026 09:10:00

Rsync version 3.4.2 and prior contain an authorization bypass vulnerability in the rsync daemon's hostname-based access control list enforcement when configured with chroot. Attackers can bypass hostname-based deny rules by controlling the PTR record...

  • EPSS 0.78%
  • Veröffentlicht 20.05.2026 00:50:21
  • Zuletzt bearbeitet 01.09.2026 13:19:32

Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for overflow, allowing a malicious sender to trigger an overflow that causes the receiver process to ...