Описание
The parse_arguments function in options.c in rsyncd in rsync before 3.1.3 does not prevent multiple --protect-args uses, which allows remote attackers to bypass an argument-sanitization protection mechanism.
| Релиз | Статус | Примечание |
|---|---|---|
| artful | released | 3.1.2-2ubuntu0.2 |
| devel | released | 3.1.2-2.1ubuntu1 |
| esm-infra-legacy/trusty | released | 3.1.0-2ubuntu0.4 |
| esm-infra/xenial | released | 3.1.1-3ubuntu1.2 |
| precise/esm | not-affected | 3.0.9-1ubuntu1.3 |
| trusty | released | 3.1.0-2ubuntu0.4 |
| trusty/esm | released | 3.1.0-2ubuntu0.4 |
| upstream | needs-triage | |
| xenial | released | 3.1.1-3ubuntu1.2 |
Показывать по
Ссылки на источники
EPSS
5 Medium
CVSS2
7.5 High
CVSS3
Связанные уязвимости
The parse_arguments function in options.c in rsyncd in rsync before 3.1.3 does not prevent multiple --protect-args uses, which allows remote attackers to bypass an argument-sanitization protection mechanism.
The parse_arguments function in options.c in rsyncd in rsync before 3.1.3 does not prevent multiple --protect-args uses, which allows remote attackers to bypass an argument-sanitization protection mechanism.
The parse_arguments function in options.c in rsyncd in rsync before 3. ...
EPSS
5 Medium
CVSS2
7.5 High
CVSS3