Количество 13
Количество 13
CVE-2026-70461
rsync 3.2.5 before 3.5.0 contains a heap out-of-bounds write vulnerability that allows remote unauthenticated attackers to write one attacker-controlled byte past the end of a heap allocation by supplying a crafted files-from entry. Attackers can trigger the vulnerability against a read-only rsync daemon module by providing a files-from entry containing both an interior and trailing backslash, causing the add_implied_include() function to under-count the trailing backslash when sizing the destination buffer.
CVE-2026-70461
rsync 3.2.5 before 3.5.0 contains a heap out-of-bounds write vulnerability that allows remote unauthenticated attackers to write one attacker-controlled byte past the end of a heap allocation by supplying a crafted files-from entry. Attackers can trigger the vulnerability against a read-only rsync daemon module by providing a files-from entry containing both an interior and trailing backslash, causing the add_implied_include() function to under-count the trailing backslash when sizing the destination buffer.
CVE-2026-70461
rsync 3.2.5 before 3.5.0 contains a heap out-of-bounds write vulnerability that allows remote unauthenticated attackers to write one attacker-controlled byte past the end of a heap allocation by supplying a crafted files-from entry. Attackers can trigger the vulnerability against a read-only rsync daemon module by providing a files-from entry containing both an interior and trailing backslash, causing the add_implied_include() function to under-count the trailing backslash when sizing the destination buffer.
CVE-2026-70461
rsync 3.2.5 < 3.5.0 Heap Out-of-Bounds Write via files-from Entry
CVE-2026-70461
rsync 3.2.5 before 3.5.0contains a heap out-of-bounds write vulnerabil ...
BDU:2026-14722
Уязвимость функции add_implied_include() сетевого демона rsync --daemon утилиты для передачи и синхронизации файлов Rsync, позволяющая нарушителю вызвать отказ в обслуживании
RLSA-2026:67462
Important: rsync security, bug fix, and enhancement update
ELSA-2026-67462-0
ELSA-2026-67462-0: rsync security, bug fix, and enhancement update (IMPORTANT)
RLSA-2026:67463
Important: rsync security, bug fix, and enhancement update
ELSA-2026-67463-0
ELSA-2026-67463-0: rsync security, bug fix, and enhancement update (IMPORTANT)
SUSE-SU-2026:3657-1
Security update for rsync
SUSE-SU-2026:3634-1
Security update for rsync
openSUSE-SU-2026:21650-1
Security update for rsync
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-70461 rsync 3.2.5 before 3.5.0 contains a heap out-of-bounds write vulnerability that allows remote unauthenticated attackers to write one attacker-controlled byte past the end of a heap allocation by supplying a crafted files-from entry. Attackers can trigger the vulnerability against a read-only rsync daemon module by providing a files-from entry containing both an interior and trailing backslash, causing the add_implied_include() function to under-count the trailing backslash when sizing the destination buffer. | CVSS3: 8.2 | 1% Низкий | около 1 месяца назад | |
CVE-2026-70461 rsync 3.2.5 before 3.5.0 contains a heap out-of-bounds write vulnerability that allows remote unauthenticated attackers to write one attacker-controlled byte past the end of a heap allocation by supplying a crafted files-from entry. Attackers can trigger the vulnerability against a read-only rsync daemon module by providing a files-from entry containing both an interior and trailing backslash, causing the add_implied_include() function to under-count the trailing backslash when sizing the destination buffer. | CVSS3: 8.2 | 1% Низкий | около 1 месяца назад | |
CVE-2026-70461 rsync 3.2.5 before 3.5.0 contains a heap out-of-bounds write vulnerability that allows remote unauthenticated attackers to write one attacker-controlled byte past the end of a heap allocation by supplying a crafted files-from entry. Attackers can trigger the vulnerability against a read-only rsync daemon module by providing a files-from entry containing both an interior and trailing backslash, causing the add_implied_include() function to under-count the trailing backslash when sizing the destination buffer. | CVSS3: 8.2 | 1% Низкий | около 1 месяца назад | |
CVE-2026-70461 rsync 3.2.5 < 3.5.0 Heap Out-of-Bounds Write via files-from Entry | CVSS3: 8.2 | 1% Низкий | 28 дней назад | |
CVE-2026-70461 rsync 3.2.5 before 3.5.0contains a heap out-of-bounds write vulnerabil ... | CVSS3: 8.2 | 1% Низкий | около 1 месяца назад | |
BDU:2026-14722 Уязвимость функции add_implied_include() сетевого демона rsync --daemon утилиты для передачи и синхронизации файлов Rsync, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 8.2 | 1% Низкий | около 1 месяца назад | |
RLSA-2026:67462 Important: rsync security, bug fix, and enhancement update | 5 дней назад | |||
ELSA-2026-67462-0 ELSA-2026-67462-0: rsync security, bug fix, and enhancement update (IMPORTANT) | 5 дней назад | |||
RLSA-2026:67463 Important: rsync security, bug fix, and enhancement update | 5 дней назад | |||
ELSA-2026-67463-0 ELSA-2026-67463-0: rsync security, bug fix, and enhancement update (IMPORTANT) | 5 дней назад | |||
SUSE-SU-2026:3657-1 Security update for rsync | около 1 месяца назад | |||
SUSE-SU-2026:3634-1 Security update for rsync | около 1 месяца назад | |||
openSUSE-SU-2026:21650-1 Security update for rsync | 25 дней назад |
Уязвимостей на страницу