Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 8

Количество 8

github логотип

GHSA-pwrq-5rj3-c43m

3 месяца назад

Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod, lchown, utimes, rename, unlink, mkdir, symlink, mknod, link, rmdir, and lstat that allow local attackers to redirect operations to files outside the exported rsync module. Attackers with local filesystem access can exploit the timing window between path resolution and syscall execution by swapping symlinks to apply sender-supplied permissions, ownership, timestamps, or filenames to arbitrary files outside the intended module boundary on rsync daemons configured with 'use chroot = no'.

CVSS3: 6.3
EPSS: Низкий
ubuntu логотип

CVE-2026-43619

3 месяца назад

Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod, lchown, utimes, rename, unlink, mkdir, symlink, mknod, link, rmdir, and lstat that allow local attackers to redirect operations to files outside the exported rsync module. Attackers with local filesystem access can exploit the timing window between path resolution and syscall execution by swapping symlinks to apply sender-supplied permissions, ownership, timestamps, or filenames to arbitrary files outside the intended module boundary on rsync daemons configured with 'use chroot = no'.

CVSS3: 6.3
EPSS: Низкий
redhat логотип

CVE-2026-43619

3 месяца назад

Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod, lchown, utimes, rename, unlink, mkdir, symlink, mknod, link, rmdir, and lstat that allow local attackers to redirect operations to files outside the exported rsync module. Attackers with local filesystem access can exploit the timing window between path resolution and syscall execution by swapping symlinks to apply sender-supplied permissions, ownership, timestamps, or filenames to arbitrary files outside the intended module boundary on rsync daemons configured with 'use chroot = no'.

CVSS3: 6.3
EPSS: Низкий
nvd логотип

CVE-2026-43619

3 месяца назад

Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod, lchown, utimes, rename, unlink, mkdir, symlink, mknod, link, rmdir, and lstat that allow local attackers to redirect operations to files outside the exported rsync module. Attackers with local filesystem access can exploit the timing window between path resolution and syscall execution by swapping symlinks to apply sender-supplied permissions, ownership, timestamps, or filenames to arbitrary files outside the intended module boundary on rsync daemons configured with 'use chroot = no'.

CVSS3: 6.3
EPSS: Низкий
msrc логотип

CVE-2026-43619

3 месяца назад

Rsync < 3.4.3 Symlink Race Condition via Path-Based Syscalls

CVSS3: 6.3
EPSS: Низкий
debian логотип

CVE-2026-43619

3 месяца назад

Rsync version3.4.2 and prior contain symlink race condition vulnerabil ...

CVSS3: 6.3
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20877-1

2 месяца назад

Security update for rsync

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2038-1

3 месяца назад

Security update for rsync

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-pwrq-5rj3-c43m

Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod, lchown, utimes, rename, unlink, mkdir, symlink, mknod, link, rmdir, and lstat that allow local attackers to redirect operations to files outside the exported rsync module. Attackers with local filesystem access can exploit the timing window between path resolution and syscall execution by swapping symlinks to apply sender-supplied permissions, ownership, timestamps, or filenames to arbitrary files outside the intended module boundary on rsync daemons configured with 'use chroot = no'.

CVSS3: 6.3
0%
Низкий
3 месяца назад
ubuntu логотип
CVE-2026-43619

Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod, lchown, utimes, rename, unlink, mkdir, symlink, mknod, link, rmdir, and lstat that allow local attackers to redirect operations to files outside the exported rsync module. Attackers with local filesystem access can exploit the timing window between path resolution and syscall execution by swapping symlinks to apply sender-supplied permissions, ownership, timestamps, or filenames to arbitrary files outside the intended module boundary on rsync daemons configured with 'use chroot = no'.

CVSS3: 6.3
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-43619

Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod, lchown, utimes, rename, unlink, mkdir, symlink, mknod, link, rmdir, and lstat that allow local attackers to redirect operations to files outside the exported rsync module. Attackers with local filesystem access can exploit the timing window between path resolution and syscall execution by swapping symlinks to apply sender-supplied permissions, ownership, timestamps, or filenames to arbitrary files outside the intended module boundary on rsync daemons configured with 'use chroot = no'.

CVSS3: 6.3
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-43619

Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod, lchown, utimes, rename, unlink, mkdir, symlink, mknod, link, rmdir, and lstat that allow local attackers to redirect operations to files outside the exported rsync module. Attackers with local filesystem access can exploit the timing window between path resolution and syscall execution by swapping symlinks to apply sender-supplied permissions, ownership, timestamps, or filenames to arbitrary files outside the intended module boundary on rsync daemons configured with 'use chroot = no'.

CVSS3: 6.3
0%
Низкий
3 месяца назад
msrc логотип
CVE-2026-43619

Rsync < 3.4.3 Symlink Race Condition via Path-Based Syscalls

CVSS3: 6.3
0%
Низкий
3 месяца назад
debian логотип
CVE-2026-43619

Rsync version3.4.2 and prior contain symlink race condition vulnerabil ...

CVSS3: 6.3
0%
Низкий
3 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20877-1

Security update for rsync

2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2038-1

Security update for rsync

3 месяца назад

Уязвимостей на страницу