Описание
rsync before 3.5.0 contains a symlink race condition vulnerability in the sender's source tree traversal that allows an attacker who can manipulate a parent directory of the source tree to redirect file reads to unintended paths. Attackers can atomically replace a parent directory component with a symlink pointing outside the source root between path resolution and file open operations to disclose file contents outside the intended transfer root.
EPSS
Процентиль: 1%
0.00092
Низкий
4.7 Medium
CVSS3
Дефекты
CWE-59
Связанные уязвимости
CVSS3: 4.7
debian
24 дня назад
rsync before 3.5.0contains a symlink race condition vulnerability in t ...
EPSS
Процентиль: 1%
0.00092
Низкий
4.7 Medium
CVSS3
Дефекты
CWE-59