rsync

Link package | bugs open | bugs closed | Wiki | GitHub | web search
Description A file transfer program to keep remote files in sync
Version 3.1.3-1 [extra]

Resolved

Group Affected Fixed Severity Status Ticket
AVG-542 3.1.2-8 3.1.3pre1-1 High Fixed FS#57111
Issue Group Severity Remote Type Description
CVE-2018-5764 AVG-542 High Yes Access restriction bypass
The parse_arguments function in options.c in rsyncd in rsync before 3.1.3 does not prevent multiple --protect-args uses, which allows remote attackers to...
CVE-2017-17434 AVG-542 Medium Yes Access restriction bypass
The daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, does not check for fnamecmp filenames in the daemon_filter_list data structure (in the...
CVE-2017-17433 AVG-542 Medium Yes Access restriction bypass
The recv_files function in receiver.c in the daemon in rsync 3.1.2, and 3.1.3-development before 2017-11-03, proceeds with certain file metadata updates...
CVE-2017-16548 AVG-542 High Yes Denial of service
The receive_xattr function in xattrs.c in rsync 3.1.2 and 3.1.3-development does not check for a trailing '\0' character in an xattr name, which allows...

Advisories

Date Advisory Group Severity Description
29 Jan 2018 ASA-201801-21 AVG-542 High multiple issues