Samba

Rsync

41 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.14%
  • Veröffentlicht 20.05.2026 00:49:14
  • Zuletzt bearbeitet 24.07.2026 09:10:00

Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod, lchown, utimes, rename, unlink, mkdir, symlink, mknod, link, rmdir, and lstat that allow local attackers to redirect operations t...

  • EPSS 0.43%
  • Veröffentlicht 20.05.2026 00:47:57
  • Zuletzt bearbeitet 24.07.2026 09:10:00

Rsync version 3.4.2 and prior contain a receiver-side out-of-bounds array read vulnerability in recv_files() in receiver.c that allows a malicious rsync server to crash the rsync client process. Attackers can exploit the vulnerability by setting CF_I...

  • EPSS 0.34%
  • Veröffentlicht 20.05.2026 00:45:28
  • Zuletzt bearbeitet 24.07.2026 09:10:00

Rsync versions before 3.4.3 contain an off-by-one out-of-bounds stack write vulnerability in the establish_proxy_connection() function in socket.c that allows network attackers to corrupt stack memory by sending a malformed HTTP proxy response. Attac...

Exploit
  • EPSS 0.39%
  • Veröffentlicht 16.04.2026 07:16:31
  • Zuletzt bearbeitet 04.09.2026 13:19:41

In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulner...

Exploit
  • EPSS 72.06%
  • Veröffentlicht 15.01.2025 15:15:10
  • Zuletzt bearbeitet 29.06.2026 21:16:29

A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), an attacker can write...

  • EPSS 4.75%
  • Veröffentlicht 14.01.2025 18:15:25
  • Zuletzt bearbeitet 30.06.2026 00:16:48

A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from the server contains another symbolic link within it. This results in a path traversal vulnerability, w...

Medienbericht Exploit
  • EPSS 2.31%
  • Veröffentlicht 14.01.2025 18:15:25
  • Zuletzt bearbeitet 30.06.2026 00:16:48

A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client options and can be enabled by the server even if not explicitly enabled by the client. When using...

Exploit
  • EPSS 1.83%
  • Veröffentlicht 14.01.2025 18:15:25
  • Zuletzt bearbeitet 21.08.2026 13:16:23

A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when files are being copied from a client to a server. During this process, the rsync server will send chec...

Exploit
  • EPSS 8.82%
  • Veröffentlicht 14.01.2025 18:15:25
  • Zuletzt bearbeitet 21.09.2026 15:17:25

A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of un...

Exploit
  • EPSS 2.17%
  • Veröffentlicht 02.08.2022 15:15:08
  • Zuletzt bearbeitet 21.11.2024 06:58:35

An issue was discovered in rsync before 3.2.5 that allows malicious remote servers to write arbitrary files inside the directories of connecting peers. The server chooses which files/directories are sent to the client. However, the rsync client perfo...