Samba

Rsync

41 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.1%
  • Veröffentlicht 27.05.2021 20:15:07
  • Zuletzt bearbeitet 21.11.2024 05:03:09

A flaw was found in rsync in versions since 3.2.0pre1. Rsync improperly validates certificate with host mismatch vulnerability. A remote, unauthenticated attacker could exploit the flaw by performing a man-in-the-middle attack using a valid certifica...

  • EPSS 6.34%
  • Veröffentlicht 17.01.2018 22:29:00
  • Zuletzt bearbeitet 21.11.2024 04:09:21

The parse_arguments function in options.c in rsyncd in rsync before 3.1.3 does not prevent multiple --protect-args uses, which allows remote attackers to bypass an argument-sanitization protection mechanism.

  • EPSS 3.36%
  • Veröffentlicht 06.12.2017 03:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

The daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, does not check for fnamecmp filenames in the daemon_filter_list data structure (in the recv_files function in receiver.c) and also does not apply the sanitize_paths protection mechan...

  • EPSS 1.79%
  • Veröffentlicht 06.12.2017 03:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

The recv_files function in receiver.c in the daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, proceeds with certain file metadata updates before checking for a filename in the daemon_filter_list data structure, which allows remote atta...

  • EPSS 5.16%
  • Veröffentlicht 06.11.2017 05:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

The receive_xattr function in xattrs.c in rsync 3.1.2 and 3.1.3-development does not check for a trailing '\0' character in an xattr name, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) ...

  • EPSS 1%
  • Veröffentlicht 29.10.2017 06:29:01
  • Zuletzt bearbeitet 13.05.2026 00:24:29

rsync 3.1.3-development before 2017-10-24 mishandles archaic checksums, which makes it easier for remote attackers to bypass intended access restrictions. NOTE: the rsync development branch has significant use beyond the rsync developers, e.g., the c...

Exploit
  • EPSS 6.5%
  • Veröffentlicht 12.02.2015 16:59:01
  • Zuletzt bearbeitet 06.05.2026 22:30:45

rsync 3.1.1 allows remote attackers to write to arbitrary files via a symlink attack on a file in the synchronization path.

  • EPSS 4.12%
  • Veröffentlicht 23.04.2014 15:55:04
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The check_secret function in authenticate.c in rsync 3.1.0 and earlier allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a user name which does not exist in the secrets file.

  • EPSS 3.19%
  • Veröffentlicht 30.03.2011 22:55:01
  • Zuletzt bearbeitet 16.06.2026 23:28:42

rsync 3.x before 3.0.8, when certain recursion, deletion, and ownership options are used, allows remote rsync servers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via malformed data.

  • EPSS 4.99%
  • Veröffentlicht 10.04.2008 19:05:00
  • Zuletzt bearbeitet 16.06.2026 22:52:21

Buffer overflow in rsync 2.6.9 to 3.0.1, with extended attribute (xattr) support enabled, might allow remote attackers to execute arbitrary code via unknown vectors.