Количество 13
Количество 13
BDU:2026-14823
Уязвимость утилиты для передачи и синхронизации файлов Rsync, связанная с некорректным определением символических ссылок перед доступом к файлу, позволяющая нарушителю повысить свои привилегии
CVE-2026-53803
rsync before 3.5.0 contains a symlink following vulnerability that allows local attackers to overwrite arbitrary files by placing a symlink at a predictable output path such as --log-file, --write-batch, or daemon-mode log and statistics paths. Attackers can exploit rsync's failure to reject symlinks during ancillary file writes to redirect output to arbitrary filesystem locations, achieving local privilege escalation on installations where rsync runs with elevated privileges such as setuid or privileged daemon configurations.
CVE-2026-53803
rsync before 3.5.0 contains a symlink following vulnerability that allows local attackers to overwrite arbitrary files by placing a symlink at a predictable output path such as --log-file, --write-batch, or daemon-mode log and statistics paths. Attackers can exploit rsync's failure to reject symlinks during ancillary file writes to redirect output to arbitrary filesystem locations, achieving local privilege escalation on installations where rsync runs with elevated privileges such as setuid or privileged daemon configurations.
CVE-2026-53803
rsync before 3.5.0 contains a symlink following vulnerability that allows local attackers to overwrite arbitrary files by placing a symlink at a predictable output path such as --log-file, --write-batch, or daemon-mode log and statistics paths. Attackers can exploit rsync's failure to reject symlinks during ancillary file writes to redirect output to arbitrary filesystem locations, achieving local privilege escalation on installations where rsync runs with elevated privileges such as setuid or privileged daemon configurations.
CVE-2026-53803
rsync < 3.5.0 Symlink Following Arbitrary File Overwrite
CVE-2026-53803
rsync before 3.5.0 contains a symlink following vulnerability that all ...
RLSA-2026:67462
Important: rsync security, bug fix, and enhancement update
ELSA-2026-67462-0
ELSA-2026-67462-0: rsync security, bug fix, and enhancement update (IMPORTANT)
RLSA-2026:67463
Important: rsync security, bug fix, and enhancement update
ELSA-2026-67463-0
ELSA-2026-67463-0: rsync security, bug fix, and enhancement update (IMPORTANT)
SUSE-SU-2026:3657-1
Security update for rsync
SUSE-SU-2026:3634-1
Security update for rsync
openSUSE-SU-2026:21650-1
Security update for rsync
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2026-14823 Уязвимость утилиты для передачи и синхронизации файлов Rsync, связанная с некорректным определением символических ссылок перед доступом к файлу, позволяющая нарушителю повысить свои привилегии | CVSS3: 7.8 | 0% Низкий | около 1 месяца назад | |
CVE-2026-53803 rsync before 3.5.0 contains a symlink following vulnerability that allows local attackers to overwrite arbitrary files by placing a symlink at a predictable output path such as --log-file, --write-batch, or daemon-mode log and statistics paths. Attackers can exploit rsync's failure to reject symlinks during ancillary file writes to redirect output to arbitrary filesystem locations, achieving local privilege escalation on installations where rsync runs with elevated privileges such as setuid or privileged daemon configurations. | CVSS3: 7.8 | 0% Низкий | около 1 месяца назад | |
CVE-2026-53803 rsync before 3.5.0 contains a symlink following vulnerability that allows local attackers to overwrite arbitrary files by placing a symlink at a predictable output path such as --log-file, --write-batch, or daemon-mode log and statistics paths. Attackers can exploit rsync's failure to reject symlinks during ancillary file writes to redirect output to arbitrary filesystem locations, achieving local privilege escalation on installations where rsync runs with elevated privileges such as setuid or privileged daemon configurations. | CVSS3: 7 | 0% Низкий | около 1 месяца назад | |
CVE-2026-53803 rsync before 3.5.0 contains a symlink following vulnerability that allows local attackers to overwrite arbitrary files by placing a symlink at a predictable output path such as --log-file, --write-batch, or daemon-mode log and statistics paths. Attackers can exploit rsync's failure to reject symlinks during ancillary file writes to redirect output to arbitrary filesystem locations, achieving local privilege escalation on installations where rsync runs with elevated privileges such as setuid or privileged daemon configurations. | CVSS3: 7.8 | 0% Низкий | около 1 месяца назад | |
CVE-2026-53803 rsync < 3.5.0 Symlink Following Arbitrary File Overwrite | 0% Низкий | 28 дней назад | ||
CVE-2026-53803 rsync before 3.5.0 contains a symlink following vulnerability that all ... | CVSS3: 7.8 | 0% Низкий | около 1 месяца назад | |
RLSA-2026:67462 Important: rsync security, bug fix, and enhancement update | 5 дней назад | |||
ELSA-2026-67462-0 ELSA-2026-67462-0: rsync security, bug fix, and enhancement update (IMPORTANT) | 5 дней назад | |||
RLSA-2026:67463 Important: rsync security, bug fix, and enhancement update | 5 дней назад | |||
ELSA-2026-67463-0 ELSA-2026-67463-0: rsync security, bug fix, and enhancement update (IMPORTANT) | 5 дней назад | |||
SUSE-SU-2026:3657-1 Security update for rsync | около 1 месяца назад | |||
SUSE-SU-2026:3634-1 Security update for rsync | около 1 месяца назад | |||
openSUSE-SU-2026:21650-1 Security update for rsync | 25 дней назад |
Уязвимостей на страницу