Skip to main content

Vendor/product archive

andrew_tridgell / rsync CVEs

Beta · best-effort

6 CVEs tagged to andrew_tridgell / rsync1 Critical, 2 High, 2 Medium, 1 Low, 0 Unrated.

CVE-2006-2083

Published Apr 28, 2006

Integer overflow in the receive_xattr function in the extended attributes patch (xattr.c) for rsync before 2.6.8 might allow attackers to execute arbitrary code via crafted extend…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-0792

Published Oct 20, 2004

Directory traversal vulnerability in the sanitize_path function in util.c for rsync 2.6.2 and earlier, when chroot is disabled, allows attackers to read or write certain files.

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0426

Published Jul 7, 2004

rsync before 2.6.1 does not properly sanitize paths when running a read/write daemon without using chroot, which allows remote attackers to write files outside of the module's pat…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-0048

Published Feb 27, 2002

Multiple signedness errors (mixed signed and unsigned numbers) in the I/O functions of rsync 2.4.6, 2.3.2, and other versions allow remote attackers to cause a denial of service a…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-0473

Published Apr 7, 1999

The rsync command before rsync 2.3.1 may inadvertently change the permissions of the client's working directory to the permissions of the directory being transferred.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1