Search CVE reports
1 – 10 of 36 results
In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common...
1 affected package
rsync
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| rsync | — | Vulnerable | Vulnerable | Vulnerable | Vulnerable |
zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.
4 affected packages
zlib, rsync, klibc, zsync
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| zlib | — | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| rsync | — | Not affected | Not affected | Vulnerable | Vulnerable |
| klibc | — | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| zsync | — | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
zlib versions up to and including 1.3.1.2 include a global buffer overflow in the untgz utility located under contrib/untgz. The vulnerability is limited to the standalone demonstration utility and does not affect the core zlib...
4 affected packages
zlib, rsync, zsync, klibc
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| zlib | — | Not affected | Not affected | Not affected | Not affected |
| rsync | — | Not affected | Not affected | Not affected | Not affected |
| zsync | — | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| klibc | — | Not affected | Not affected | Not affected | Not affected |
A malicious client acting as the receiver of an rsync file transfer can trigger an out of bounds read of a heap based buffer, via a negative array index. The malicious rsync client requires at least read access to the remote rsync...
1 affected package
rsync
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| rsync | — | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
A flaw was found in rsync. This vulnerability arises from a race condition during rsync's handling of symbolic links. Rsync's default behavior when encountering symbolic links is to skip them. If an attacker replaced a regular...
1 affected package
rsync
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| rsync | — | Fixed | Fixed | Fixed | Fixed |
A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from the server contains another symbolic link within it. This results in a...
1 affected package
rsync
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| rsync | — | Fixed | Fixed | Fixed | Fixed |
A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client options and can be enabled by the server even if not explicitly enabled by...
1 affected package
rsync
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| rsync | — | Fixed | Fixed | Fixed | Fixed |
A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when files are being copied from a client to a server. During this process, the rsync...
1 affected package
rsync
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| rsync | — | Fixed | Fixed | Fixed | Fixed |
A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and...
1 affected package
rsync
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| rsync | — | Fixed | Fixed | Fixed | Fixed |
A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes),...
1 affected package
rsync
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| rsync | — | Fixed | Fixed | Not affected | Not affected |