Количество 13
Количество 13
BDU:2026-14820
Уязвимость утилиты для передачи и синхронизации файлов Rsync, связанная с непринятием мер по нейтрализации специальных элементов, позволяющая нарушителю выполнить произвольные команды
CVE-2026-53790
rsync before 3.5.0 contains multiple command and argument injection vulnerabilities that allow attackers to execute arbitrary commands by supplying malicious input through several code paths, including the RSYNC_CONNECT_PROG environment variable, daemon hooks, the rsync-ssl wrapper, and remote-shell command newline injection. Attackers can inject shell metacharacters or newline characters into unsanitized user-supplied values such as hostnames and hostspecs to execute arbitrary commands under the privileges of the rsync process or the invoking user.
CVE-2026-53790
rsync before 3.5.0 contains multiple command and argument injection vulnerabilities that allow attackers to execute arbitrary commands by supplying malicious input through several code paths, including the RSYNC_CONNECT_PROG environment variable, daemon hooks, the rsync-ssl wrapper, and remote-shell command newline injection. Attackers can inject shell metacharacters or newline characters into unsanitized user-supplied values such as hostnames and hostspecs to execute arbitrary commands under the privileges of the rsync process or the invoking user.
CVE-2026-53790
rsync before 3.5.0 contains multiple command and argument injection vulnerabilities that allow attackers to execute arbitrary commands by supplying malicious input through several code paths, including the RSYNC_CONNECT_PROG environment variable, daemon hooks, the rsync-ssl wrapper, and remote-shell command newline injection. Attackers can inject shell metacharacters or newline characters into unsanitized user-supplied values such as hostnames and hostspecs to execute arbitrary commands under the privileges of the rsync process or the invoking user.
CVE-2026-53790
rsync < 3.5.0 Command Injection via Multiple Code Paths
CVE-2026-53790
rsync before 3.5.0contains multiple command and argument injection vul ...
RLSA-2026:67462
Important: rsync security, bug fix, and enhancement update
ELSA-2026-67462-0
ELSA-2026-67462-0: rsync security, bug fix, and enhancement update (IMPORTANT)
RLSA-2026:67463
Important: rsync security, bug fix, and enhancement update
ELSA-2026-67463-0
ELSA-2026-67463-0: rsync security, bug fix, and enhancement update (IMPORTANT)
SUSE-SU-2026:3657-1
Security update for rsync
SUSE-SU-2026:3634-1
Security update for rsync
openSUSE-SU-2026:21650-1
Security update for rsync
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2026-14820 Уязвимость утилиты для передачи и синхронизации файлов Rsync, связанная с непринятием мер по нейтрализации специальных элементов, позволяющая нарушителю выполнить произвольные команды | CVSS3: 8.1 | 1% Низкий | около 1 месяца назад | |
CVE-2026-53790 rsync before 3.5.0 contains multiple command and argument injection vulnerabilities that allow attackers to execute arbitrary commands by supplying malicious input through several code paths, including the RSYNC_CONNECT_PROG environment variable, daemon hooks, the rsync-ssl wrapper, and remote-shell command newline injection. Attackers can inject shell metacharacters or newline characters into unsanitized user-supplied values such as hostnames and hostspecs to execute arbitrary commands under the privileges of the rsync process or the invoking user. | CVSS3: 8.1 | 1% Низкий | около 1 месяца назад | |
CVE-2026-53790 rsync before 3.5.0 contains multiple command and argument injection vulnerabilities that allow attackers to execute arbitrary commands by supplying malicious input through several code paths, including the RSYNC_CONNECT_PROG environment variable, daemon hooks, the rsync-ssl wrapper, and remote-shell command newline injection. Attackers can inject shell metacharacters or newline characters into unsanitized user-supplied values such as hostnames and hostspecs to execute arbitrary commands under the privileges of the rsync process or the invoking user. | CVSS3: 8.1 | 1% Низкий | около 1 месяца назад | |
CVE-2026-53790 rsync before 3.5.0 contains multiple command and argument injection vulnerabilities that allow attackers to execute arbitrary commands by supplying malicious input through several code paths, including the RSYNC_CONNECT_PROG environment variable, daemon hooks, the rsync-ssl wrapper, and remote-shell command newline injection. Attackers can inject shell metacharacters or newline characters into unsanitized user-supplied values such as hostnames and hostspecs to execute arbitrary commands under the privileges of the rsync process or the invoking user. | CVSS3: 8.1 | 1% Низкий | около 1 месяца назад | |
CVE-2026-53790 rsync < 3.5.0 Command Injection via Multiple Code Paths | 1% Низкий | 28 дней назад | ||
CVE-2026-53790 rsync before 3.5.0contains multiple command and argument injection vul ... | CVSS3: 8.1 | 1% Низкий | около 1 месяца назад | |
RLSA-2026:67462 Important: rsync security, bug fix, and enhancement update | 5 дней назад | |||
ELSA-2026-67462-0 ELSA-2026-67462-0: rsync security, bug fix, and enhancement update (IMPORTANT) | 5 дней назад | |||
RLSA-2026:67463 Important: rsync security, bug fix, and enhancement update | 5 дней назад | |||
ELSA-2026-67463-0 ELSA-2026-67463-0: rsync security, bug fix, and enhancement update (IMPORTANT) | 5 дней назад | |||
SUSE-SU-2026:3657-1 Security update for rsync | около 1 месяца назад | |||
SUSE-SU-2026:3634-1 Security update for rsync | около 1 месяца назад | |||
openSUSE-SU-2026:21650-1 Security update for rsync | 25 дней назад |
Уязвимостей на страницу