Debian Rsync vulnerabilities
30 known vulnerabilities affecting debian/rsync.
Total CVEs
30
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH10MEDIUM9LOW6
Vulnerabilities
Page 2 of 2
CVE-2007-4091P3MEDIUMCVSS 6.8fixed in rsync 2.6.9-5 (bookworm)2007
CVE-2007-4091 [MEDIUM] CVE-2007-4091: rsync - Multiple off-by-one errors in the sender.c in rsync 2.6.9 might allow remote att...
Multiple off-by-one errors in the sender.c in rsync 2.6.9 might allow remote attackers to execute arbitrary code via directory names that are not properly handled when calling the f_name function.
Scope: local
bookworm: resolved (fixed in 2.6.9-5)
bullseye: resolved (fixed in 2.6.9-5)
forky: resolved (fixed in 2.6.9-5)
sid: resolved (fixed in 2.6.9-5)
trixie: resolved
debian
CVE-2014-2855P3HIGHCVSS 7.8fixed in rsync 3.1.0-3 (bookworm)2014
CVE-2014-2855 [HIGH] CVE-2014-2855: rsync - The check_secret function in authenticate.c in rsync 3.1.0 and earlier allows re...
The check_secret function in authenticate.c in rsync 3.1.0 and earlier allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a user name which does not exist in the secrets file.
Scope: local
bookworm: resolved (fixed in 3.1.0-3)
bullseye: resolved (fixed in 3.1.0-3)
forky: resolved (fixed in 3.1.0-3)
sid: resolved (fixed in 3.1.0-
debian
CVE-2006-2083P4HIGHCVSS 7.5fixed in rsync 2.6.8-1 (bookworm)2006
CVE-2006-2083 [HIGH] CVE-2006-2083: rsync - Integer overflow in the receive_xattr function in the extended attributes patch ...
Integer overflow in the receive_xattr function in the extended attributes patch (xattr.c) for rsync before 2.6.8 might allow attackers to execute arbitrary code via crafted extended attributes that trigger a buffer overflow.
Scope: local
bookworm: resolved (fixed in 2.6.8-1)
bullseye: resolved (fixed in 2.6.8-1)
forky: resolved (fixed in 2.6.8-1)
sid: resolved (fixed in
debian
CVE-2005-2096P4LOWCVSS 7.5fixed in aide 0.10-6.1.1 (bookworm)2005
CVE-2005-2096 [HIGH] CVE-2005-2096: aide - zlib 1.2 and later versions allows remote attackers to cause a denial of service...
zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete code description of a length greater than 1, which leads to a buffer overflow, as demonstrated using a crafted PNG file.
Scope: local
bookworm: resolved (fixed in 0.10-6.1.1)
bullseye: resolved (fixed in 0.10-6.1.1)
forky: resolved (
debian
CVE-2011-1097P4LOWCVSS 5.1fixed in rsync 3.0.8 (bookworm)2011
CVE-2011-1097 [MEDIUM] CVE-2011-1097: rsync - rsync 3.x before 3.0.8, when certain recursion, deletion, and ownership options ...
rsync 3.x before 3.0.8, when certain recursion, deletion, and ownership options are used, allows remote rsync servers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via malformed data.
Scope: local
bookworm: resolved (fixed in 3.0.8)
bullseye: resolved (fixed in 3.0.8)
forky: resolved (fixed in 3.0.8)
sid
debian
CVE-2024-12747P4MEDIUMCVSS 5.6fixed in rsync 3.2.7-1+deb12u1 (bookworm)2024
CVE-2024-12747 [MEDIUM] CVE-2024-12747: rsync - A flaw was found in rsync. This vulnerability arises from a race condition durin...
A flaw was found in rsync. This vulnerability arises from a race condition during rsync's handling of symbolic links. Rsync's default behavior when encountering symbolic links is to skip them. If an attacker replaced a regular file with a symbolic link at the right time, it was possible to bypass the default behavior and traverse symbolic links. Depending on the pri
debian
CVE-2004-0426P4MEDIUMCVSS 5.0fixed in rsync 2.6.1-1 (bookworm)2004
CVE-2004-0426 [MEDIUM] CVE-2004-0426: rsync - rsync before 2.6.1 does not properly sanitize paths when running a read/write da...
rsync before 2.6.1 does not properly sanitize paths when running a read/write daemon without using chroot, which allows remote attackers to write files outside of the module's path.
Scope: local
bookworm: resolved (fixed in 2.6.1-1)
bullseye: resolved (fixed in 2.6.1-1)
forky: resolved (fixed in 2.6.1-1)
sid: resolved (fixed in 2.6.1-1)
trixie: resolved (fixed in 2.6.
debian
CVE-2025-10158P4MEDIUMCVSS 4.3fixed in rsync 3.2.7-1+deb12u4 (bookworm)2025
CVE-2025-10158 [MEDIUM] CVE-2025-10158: rsync - A malicious client acting as the receiver of an rsync file transfer can trigger ...
A malicious client acting as the receiver of an rsync file transfer can trigger an out of bounds read of a heap based buffer, via a negative array index. The malicious rsync client requires at least read access to the remote rsync module in order to trigger the issue.
Scope: local
bookworm: resolved (fixed in 3.2.7-1+deb12u4)
bullseye: open
forky: resolved (fixed in
debian
CVE-2004-0792P4MEDIUMCVSS 6.4fixed in rsync 2.6.2-3 (bookworm)2004
CVE-2004-0792 [MEDIUM] CVE-2004-0792: rsync - Directory traversal vulnerability in the sanitize_path function in util.c for rs...
Directory traversal vulnerability in the sanitize_path function in util.c for rsync 2.6.2 and earlier, when chroot is disabled, allows attackers to read or write certain files.
Scope: local
bookworm: resolved (fixed in 2.6.2-3)
bullseye: resolved (fixed in 2.6.2-3)
forky: resolved (fixed in 2.6.2-3)
sid: resolved (fixed in 2.6.2-3)
trixie: resolved (fixed in 2.6.2-3)
debian
CVE-2017-17433P4LOWCVSS 3.7fixed in rsync 3.1.2-2.1 (bookworm)2017
CVE-2017-17433 [LOW] CVE-2017-17433: rsync - The recv_files function in receiver.c in the daemon in rsync 3.1.2, and 3.1.3-de...
The recv_files function in receiver.c in the daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, proceeds with certain file metadata updates before checking for a filename in the daemon_filter_list data structure, which allows remote attackers to bypass intended access restrictions.
Scope: local
bookworm: resolved (fixed in 3.1.2-2.1)
bullseye: resolved (fi
debian
← Previous2 / 2