CVE-2020-14387
- EPSS 1.1%
- Veröffentlicht 27.05.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 05:03:09
A flaw was found in rsync in versions since 3.2.0pre1. Rsync improperly validates certificate with host mismatch vulnerability. A remote, unauthenticated attacker could exploit the flaw by performing a man-in-the-middle attack using a valid certifica...
CVE-2018-5764
- EPSS 6.34%
- Veröffentlicht 17.01.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:09:21
The parse_arguments function in options.c in rsyncd in rsync before 3.1.3 does not prevent multiple --protect-args uses, which allows remote attackers to bypass an argument-sanitization protection mechanism.
CVE-2017-17434
- EPSS 3.36%
- Veröffentlicht 06.12.2017 03:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, does not check for fnamecmp filenames in the daemon_filter_list data structure (in the recv_files function in receiver.c) and also does not apply the sanitize_paths protection mechan...
CVE-2017-17433
- EPSS 1.79%
- Veröffentlicht 06.12.2017 03:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The recv_files function in receiver.c in the daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, proceeds with certain file metadata updates before checking for a filename in the daemon_filter_list data structure, which allows remote atta...
CVE-2017-16548
- EPSS 5.16%
- Veröffentlicht 06.11.2017 05:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The receive_xattr function in xattrs.c in rsync 3.1.2 and 3.1.3-development does not check for a trailing '\0' character in an xattr name, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) ...
CVE-2017-15994
- EPSS 1%
- Veröffentlicht 29.10.2017 06:29:01
- Zuletzt bearbeitet 13.05.2026 00:24:29
rsync 3.1.3-development before 2017-10-24 mishandles archaic checksums, which makes it easier for remote attackers to bypass intended access restrictions. NOTE: the rsync development branch has significant use beyond the rsync developers, e.g., the c...
CVE-2014-9512
- EPSS 6.5%
- Veröffentlicht 12.02.2015 16:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
rsync 3.1.1 allows remote attackers to write to arbitrary files via a symlink attack on a file in the synchronization path.
CVE-2014-2855
- EPSS 4.12%
- Veröffentlicht 23.04.2014 15:55:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
The check_secret function in authenticate.c in rsync 3.1.0 and earlier allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a user name which does not exist in the secrets file.
CVE-2011-1097
- EPSS 3.19%
- Veröffentlicht 30.03.2011 22:55:01
- Zuletzt bearbeitet 16.06.2026 23:28:42
rsync 3.x before 3.0.8, when certain recursion, deletion, and ownership options are used, allows remote rsync servers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via malformed data.
CVE-2008-1720
- EPSS 4.99%
- Veröffentlicht 10.04.2008 19:05:00
- Zuletzt bearbeitet 16.06.2026 22:52:21
Buffer overflow in rsync 2.6.9 to 3.0.1, with extended attribute (xattr) support enabled, might allow remote attackers to execute arbitrary code via unknown vectors.