Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-45232

Опубликовано: 20 мая 2026
Источник: nvd
CVSS3: 3.1
CVSS3: 3.7
EPSS Низкий

Описание

Rsync versions before 3.4.3 contain an off-by-one out-of-bounds stack write vulnerability in the establish_proxy_connection() function in socket.c that allows network attackers to corrupt stack memory by sending a malformed HTTP proxy response. Attackers can exploit this by positioning themselves between the client and proxy or controlling the proxy server to send a response line of 1023 or more bytes without a newline terminator, causing a null byte to be written to an out-of-bounds stack address when the RSYNC_PROXY environment variable is set.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:samba:rsync:*:*:*:*:*:*:*:*
Версия до 3.4.3 (исключая)

EPSS

Процентиль: 26%
0.00337
Низкий

3.1 Low

CVSS3

3.7 Low

CVSS3

Дефекты

CWE-193

Связанные уязвимости

CVSS3: 3.1
ubuntu
3 месяца назад

Rsync versions before 3.4.3 contain an off-by-one out-of-bounds stack write vulnerability in the establish_proxy_connection() function in socket.c that allows network attackers to corrupt stack memory by sending a malformed HTTP proxy response. Attackers can exploit this by positioning themselves between the client and proxy or controlling the proxy server to send a response line of 1023 or more bytes without a newline terminator, causing a null byte to be written to an out-of-bounds stack address when the RSYNC_PROXY environment variable is set.

CVSS3: 5.9
redhat
3 месяца назад

Rsync versions before 3.4.3 contain an off-by-one out-of-bounds stack write vulnerability in the establish_proxy_connection() function in socket.c that allows network attackers to corrupt stack memory by sending a malformed HTTP proxy response. Attackers can exploit this by positioning themselves between the client and proxy or controlling the proxy server to send a response line of 1023 or more bytes without a newline terminator, causing a null byte to be written to an out-of-bounds stack address when the RSYNC_PROXY environment variable is set.

CVSS3: 3.1
msrc
3 месяца назад

Rsync < 3.4.3 Off-by-One Stack Write via HTTP Proxy

CVSS3: 3.1
debian
3 месяца назад

Rsync versions before 3.4.3 contain an off-by-one out-of-bounds stack ...

suse-cvrf
2 месяца назад

Security update for rsync

EPSS

Процентиль: 26%
0.00337
Низкий

3.1 Low

CVSS3

3.7 Low

CVSS3

Дефекты

CWE-193