Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 36

Количество 36

ubuntu логотип

CVE-2024-12747

больше 1 года назад

A flaw was found in rsync. This vulnerability arises from a race condition during rsync's handling of symbolic links. Rsync's default behavior when encountering symbolic links is to skip them. If an attacker replaced a regular file with a symbolic link at the right time, it was possible to bypass the default behavior and traverse symbolic links. Depending on the privileges of the rsync process, an attacker could leak sensitive information, potentially leading to privilege escalation.

CVSS3: 5.6
EPSS: Низкий
redhat логотип

CVE-2024-12747

больше 1 года назад

A flaw was found in rsync. This vulnerability arises from a race condition during rsync's handling of symbolic links. Rsync's default behavior when encountering symbolic links is to skip them. If an attacker replaced a regular file with a symbolic link at the right time, it was possible to bypass the default behavior and traverse symbolic links. Depending on the privileges of the rsync process, an attacker could leak sensitive information, potentially leading to privilege escalation.

CVSS3: 5.6
EPSS: Низкий
nvd логотип

CVE-2024-12747

больше 1 года назад

A flaw was found in rsync. This vulnerability arises from a race condition during rsync's handling of symbolic links. Rsync's default behavior when encountering symbolic links is to skip them. If an attacker replaced a regular file with a symbolic link at the right time, it was possible to bypass the default behavior and traverse symbolic links. Depending on the privileges of the rsync process, an attacker could leak sensitive information, potentially leading to privilege escalation.

CVSS3: 5.6
EPSS: Низкий
msrc логотип

CVE-2024-12747

больше 1 года назад

Rsync: race condition in rsync handling symbolic links

CVSS3: 5.6
EPSS: Низкий
debian логотип

CVE-2024-12747

больше 1 года назад

A flaw was found in rsync. This vulnerability arises from a race condi ...

CVSS3: 5.6
EPSS: Низкий
ubuntu логотип

CVE-2024-12087

больше 1 года назад

A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client options and can be enabled by the server even if not explicitly enabled by the client. When using the `--inc-recursive` option, a lack of proper symlink verification coupled with deduplication checks occurring on a per-file-list basis could allow a server to write files outside of the client's intended destination directory. A malicious server could write malicious files to arbitrary locations named after valid directories/paths on the client.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2024-12087

больше 1 года назад

A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client options and can be enabled by the server even if not explicitly enabled by the client. When using the `--inc-recursive` option, a lack of proper symlink verification coupled with deduplication checks occurring on a per-file-list basis could allow a server to write files outside of the client's intended destination directory. A malicious server could write malicious files to arbitrary locations named after valid directories/paths on the client.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2024-12087

больше 1 года назад

A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client options and can be enabled by the server even if not explicitly enabled by the client. When using the `--inc-recursive` option, a lack of proper symlink verification coupled with deduplication checks occurring on a per-file-list basis could allow a server to write files outside of the client's intended destination directory. A malicious server could write malicious files to arbitrary locations named after valid directories/paths on the client.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2024-12087

больше 1 года назад

Rsync: path traversal vulnerability in rsync

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2024-12087

больше 1 года назад

A path traversal vulnerability exists in rsync. It stems from behavior ...

CVSS3: 6.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0991-1

больше 1 года назад

Security update for rsync

EPSS: Низкий
github логотип

GHSA-gp7r-m4cc-qhwq

больше 1 года назад

A flaw was found in rsync. This vulnerability arises from a race condition during rsync's handling of symbolic links. Rsync's default behavior when encountering symbolic links is to skip them. If an attacker replaced a regular file with a symbolic link at the right time, it was possible to bypass the default behavior and traverse symbolic links. Depending on the privileges of the rsync process, an attacker could leak sensitive information, potentially leading to privilege escalation.

CVSS3: 5.6
EPSS: Низкий
github логотип

GHSA-9x68-7qq6-v523

больше 1 года назад

A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client options and can be enabled by the server even if not explicitly enabled by the client. When using the `--inc-recursive` option, a lack of proper symlink verification coupled with deduplication checks occurring on a per-file-list basis could allow a server to write files outside of the client's intended destination directory. A malicious server could write malicious files to arbitrary locations named after valid directories/paths on the client.

CVSS3: 6.5
EPSS: Низкий
oracle-oval логотип

ELSA-2025-23415

7 месяцев назад

ELSA-2025-23415: rsync security update (MODERATE)

EPSS: Низкий
fstec логотип

BDU:2025-00377

больше 1 года назад

Уязвимость конфигурации --inc-recursive демона rsyncd утилиты для передачи и синхронизации файлов Rsync, позволяющая нарушителю записывать произвольные файлы

CVSS3: 6.5
EPSS: Низкий
fstec логотип

BDU:2025-00372

больше 1 года назад

Уязвимость утилиты для передачи и синхронизации файлов Rsync, связанная с ошибками синхронизации при использовании общего ресурса, позволяющая нарушителю повысить свои привилегии

CVSS3: 5.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-12747

A flaw was found in rsync. This vulnerability arises from a race condition during rsync's handling of symbolic links. Rsync's default behavior when encountering symbolic links is to skip them. If an attacker replaced a regular file with a symbolic link at the right time, it was possible to bypass the default behavior and traverse symbolic links. Depending on the privileges of the rsync process, an attacker could leak sensitive information, potentially leading to privilege escalation.

CVSS3: 5.6
0%
Низкий
больше 1 года назад
redhat логотип
CVE-2024-12747

A flaw was found in rsync. This vulnerability arises from a race condition during rsync's handling of symbolic links. Rsync's default behavior when encountering symbolic links is to skip them. If an attacker replaced a regular file with a symbolic link at the right time, it was possible to bypass the default behavior and traverse symbolic links. Depending on the privileges of the rsync process, an attacker could leak sensitive information, potentially leading to privilege escalation.

CVSS3: 5.6
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-12747

A flaw was found in rsync. This vulnerability arises from a race condition during rsync's handling of symbolic links. Rsync's default behavior when encountering symbolic links is to skip them. If an attacker replaced a regular file with a symbolic link at the right time, it was possible to bypass the default behavior and traverse symbolic links. Depending on the privileges of the rsync process, an attacker could leak sensitive information, potentially leading to privilege escalation.

CVSS3: 5.6
0%
Низкий
больше 1 года назад
msrc логотип
CVE-2024-12747

Rsync: race condition in rsync handling symbolic links

CVSS3: 5.6
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-12747

A flaw was found in rsync. This vulnerability arises from a race condi ...

CVSS3: 5.6
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-12087

A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client options and can be enabled by the server even if not explicitly enabled by the client. When using the `--inc-recursive` option, a lack of proper symlink verification coupled with deduplication checks occurring on a per-file-list basis could allow a server to write files outside of the client's intended destination directory. A malicious server could write malicious files to arbitrary locations named after valid directories/paths on the client.

CVSS3: 6.5
2%
Низкий
больше 1 года назад
redhat логотип
CVE-2024-12087

A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client options and can be enabled by the server even if not explicitly enabled by the client. When using the `--inc-recursive` option, a lack of proper symlink verification coupled with deduplication checks occurring on a per-file-list basis could allow a server to write files outside of the client's intended destination directory. A malicious server could write malicious files to arbitrary locations named after valid directories/paths on the client.

CVSS3: 6.5
2%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-12087

A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client options and can be enabled by the server even if not explicitly enabled by the client. When using the `--inc-recursive` option, a lack of proper symlink verification coupled with deduplication checks occurring on a per-file-list basis could allow a server to write files outside of the client's intended destination directory. A malicious server could write malicious files to arbitrary locations named after valid directories/paths on the client.

CVSS3: 6.5
2%
Низкий
больше 1 года назад
msrc логотип
CVE-2024-12087

Rsync: path traversal vulnerability in rsync

CVSS3: 6.5
2%
Низкий
больше 1 года назад
debian логотип
CVE-2024-12087

A path traversal vulnerability exists in rsync. It stems from behavior ...

CVSS3: 6.5
2%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2025:0991-1

Security update for rsync

0%
Низкий
больше 1 года назад
github логотип
GHSA-gp7r-m4cc-qhwq

A flaw was found in rsync. This vulnerability arises from a race condition during rsync's handling of symbolic links. Rsync's default behavior when encountering symbolic links is to skip them. If an attacker replaced a regular file with a symbolic link at the right time, it was possible to bypass the default behavior and traverse symbolic links. Depending on the privileges of the rsync process, an attacker could leak sensitive information, potentially leading to privilege escalation.

CVSS3: 5.6
0%
Низкий
больше 1 года назад
github логотип
GHSA-9x68-7qq6-v523

A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client options and can be enabled by the server even if not explicitly enabled by the client. When using the `--inc-recursive` option, a lack of proper symlink verification coupled with deduplication checks occurring on a per-file-list basis could allow a server to write files outside of the client's intended destination directory. A malicious server could write malicious files to arbitrary locations named after valid directories/paths on the client.

CVSS3: 6.5
2%
Низкий
больше 1 года назад
oracle-oval логотип
ELSA-2025-23415

ELSA-2025-23415: rsync security update (MODERATE)

2%
Низкий
7 месяцев назад
fstec логотип
BDU:2025-00377

Уязвимость конфигурации --inc-recursive демона rsyncd утилиты для передачи и синхронизации файлов Rsync, позволяющая нарушителю записывать произвольные файлы

CVSS3: 6.5
2%
Низкий
больше 1 года назад
fstec логотип
BDU:2025-00372

Уязвимость утилиты для передачи и синхронизации файлов Rsync, связанная с ошибками синхронизации при использовании общего ресурса, позволяющая нарушителю повысить свои привилегии

CVSS3: 5.6
0%
Низкий
больше 1 года назад

Уязвимостей на страницу