Search CVE reports
1 – 10 of 32 results
CVE-2024-12747
Medium prioritySome fixes available 5 of 7
A flaw was found in rsync. This vulnerability arises from a race condition during rsync's handling of symbolic links. Rsync's default behavior when encountering symbolic links is to skip them. If an attacker replaced a regular...
1 affected package
rsync
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
rsync | Fixed | Fixed | Fixed | Fixed | Fixed |
CVE-2024-12088
Medium prioritySome fixes available 5 of 7
A flaw was found in rsync. When using the `--safe-links` option, rsync fails to properly verify if a symbolic link destination contains another symbolic link within it. This results in a path traversal vulnerability, which may...
1 affected package
rsync
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
rsync | Fixed | Fixed | Fixed | Fixed | Fixed |
CVE-2024-12087
Medium prioritySome fixes available 5 of 7
A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client options and can be enabled by the server even if not explicitly enabled by...
1 affected package
rsync
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
rsync | Fixed | Fixed | Fixed | Fixed | Fixed |
CVE-2024-12086
Medium prioritySome fixes available 5 of 7
A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when files are being copied from a client to a server. During this process, the rsync...
1 affected package
rsync
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
rsync | Fixed | Fixed | Fixed | Fixed | Fixed |
CVE-2024-12085
Medium prioritySome fixes available 5 of 7
A flaw was found in the rsync daemon which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized...
1 affected package
rsync
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
rsync | Fixed | Fixed | Fixed | Fixed | Fixed |
CVE-2024-12084
High prioritySome fixes available 2 of 3
[Heap Buffer Overflow in Checksum Parsing]
1 affected package
rsync
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
rsync | Fixed | Fixed | Not affected | Not affected | Not affected |
CVE-2023-45853
Medium priorityMiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE:...
3 affected packages
klibc, rsync, zlib
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
klibc | Not affected | Not affected | Not affected | Not affected | Not affected |
rsync | Not affected | Not affected | Not affected | Not affected | Not affected |
zlib | Not affected | Not affected | Not affected | Not affected | Not affected |
CVE-2022-42800
Medium priorityThis issue was addressed with improved checks. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, watchOS 9.1, iOS 16.1 and iPadOS 16, macOS Monterey 12.6.1, macOS Big Sur 11.7.1. A user may be able to cause...
2 affected packages
rsync, zlib
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
rsync | — | Not affected | Not affected | Not affected | Not affected |
zlib | — | Not affected | Not affected | Not affected | Not affected |
CVE-2022-37434
Medium priorityzlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle...
3 affected packages
klibc, rsync, zlib
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
klibc | Fixed | Fixed | Fixed | Fixed | Fixed |
rsync | Not affected | Not affected | Fixed | Fixed | Fixed |
zlib | Not affected | Fixed | Fixed | Fixed | Fixed |
CVE-2022-29154
Medium prioritySome fixes available 3 of 5
An issue was discovered in rsync before 3.2.5 that allows malicious remote servers to write arbitrary files inside the directories of connecting peers. The server chooses which files/directories are sent to the client. However,...
1 affected package
rsync
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
rsync | — | Fixed | Fixed | Fixed | Ignored |