Количество 16
Количество 16
CVE-2026-43618
Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for overflow, allowing a malicious sender to trigger an overflow that causes the receiver process to read and return data from outside the intended buffer bounds. Attackers can exploit this vulnerability to disclose process memory contents including environment variables, passwords, heap and stack data, and library memory pointers, significantly reducing ASLR effectiveness and facilitating further exploitation.
CVE-2026-43618
Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for overflow, allowing a malicious sender to trigger an overflow that causes the receiver process to read and return data from outside the intended buffer bounds. Attackers can exploit this vulnerability to disclose process memory contents including environment variables, passwords, heap and stack data, and library memory pointers, significantly reducing ASLR effectiveness and facilitating further exploitation.
CVE-2026-43618
Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for overflow, allowing a malicious sender to trigger an overflow that causes the receiver process to read and return data from outside the intended buffer bounds. Attackers can exploit this vulnerability to disclose process memory contents including environment variables, passwords, heap and stack data, and library memory pointers, significantly reducing ASLR effectiveness and facilitating further exploitation.
CVE-2026-43618
Rsync < 3.4.3 Integer Overflow Information Disclosure
CVE-2026-43618
Rsync version3.4.2 and prior contain an integer overflow vulnerability ...
GHSA-88m5-cm5m-2596
Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for overflow, allowing a malicious sender to trigger an overflow that causes the receiver process to read and return data from outside the intended buffer bounds. Attackers can exploit this vulnerability to disclose process memory contents including environment variables, passwords, heap and stack data, and library memory pointers, significantly reducing ASLR effectiveness and facilitating further exploitation.
RLSA-2026:26410
Important: rsync security update
RLSA-2026:26408
Important: rsync security update
RLSA-2026:26332
Important: rsync security, bug fix, and enhancement update
ELSA-2026-26410
ELSA-2026-26410: rsync security update (IMPORTANT)
ELSA-2026-26408
ELSA-2026-26408: rsync security update (IMPORTANT)
ELSA-2026-26332
ELSA-2026-26332: rsync security, bug fix, and enhancement update (IMPORTANT)
openSUSE-SU-2026:20877-1
Security update for rsync
SUSE-SU-2026:2083-1
Security update for rsync
SUSE-SU-2026:2048-1
Security update for rsync
SUSE-SU-2026:2038-1
Security update for rsync
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-43618 Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for overflow, allowing a malicious sender to trigger an overflow that causes the receiver process to read and return data from outside the intended buffer bounds. Attackers can exploit this vulnerability to disclose process memory contents including environment variables, passwords, heap and stack data, and library memory pointers, significantly reducing ASLR effectiveness and facilitating further exploitation. | CVSS3: 8.1 | 1% Низкий | 2 месяца назад | |
CVE-2026-43618 Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for overflow, allowing a malicious sender to trigger an overflow that causes the receiver process to read and return data from outside the intended buffer bounds. Attackers can exploit this vulnerability to disclose process memory contents including environment variables, passwords, heap and stack data, and library memory pointers, significantly reducing ASLR effectiveness and facilitating further exploitation. | CVSS3: 8.1 | 1% Низкий | 2 месяца назад | |
CVE-2026-43618 Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for overflow, allowing a malicious sender to trigger an overflow that causes the receiver process to read and return data from outside the intended buffer bounds. Attackers can exploit this vulnerability to disclose process memory contents including environment variables, passwords, heap and stack data, and library memory pointers, significantly reducing ASLR effectiveness and facilitating further exploitation. | CVSS3: 8.1 | 1% Низкий | 2 месяца назад | |
CVE-2026-43618 Rsync < 3.4.3 Integer Overflow Information Disclosure | CVSS3: 8.1 | 1% Низкий | 2 месяца назад | |
CVE-2026-43618 Rsync version3.4.2 and prior contain an integer overflow vulnerability ... | CVSS3: 8.1 | 1% Низкий | 2 месяца назад | |
GHSA-88m5-cm5m-2596 Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for overflow, allowing a malicious sender to trigger an overflow that causes the receiver process to read and return data from outside the intended buffer bounds. Attackers can exploit this vulnerability to disclose process memory contents including environment variables, passwords, heap and stack data, and library memory pointers, significantly reducing ASLR effectiveness and facilitating further exploitation. | CVSS3: 8.1 | 1% Низкий | 2 месяца назад | |
RLSA-2026:26410 Important: rsync security update | около 2 месяцев назад | |||
RLSA-2026:26408 Important: rsync security update | около 2 месяцев назад | |||
RLSA-2026:26332 Important: rsync security, bug fix, and enhancement update | около 1 месяца назад | |||
ELSA-2026-26410 ELSA-2026-26410: rsync security update (IMPORTANT) | около 1 месяца назад | |||
ELSA-2026-26408 ELSA-2026-26408: rsync security update (IMPORTANT) | около 2 месяцев назад | |||
ELSA-2026-26332 ELSA-2026-26332: rsync security, bug fix, and enhancement update (IMPORTANT) | 17 дней назад | |||
openSUSE-SU-2026:20877-1 Security update for rsync | 2 месяца назад | |||
SUSE-SU-2026:2083-1 Security update for rsync | 2 месяца назад | |||
SUSE-SU-2026:2048-1 Security update for rsync | 2 месяца назад | |||
SUSE-SU-2026:2038-1 Security update for rsync | 2 месяца назад |
Уязвимостей на страницу