Search CVE reports
1001 – 1010 of 55618 results
rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks within the module file tree when using --partial-dir or --backup-dir options....
1 affected package
rsync
| Package | 16.04 LTS |
|---|---|
| rsync | Needs evaluation |
rsync 3.0.0 before 3.5.0 contains a null pointer dereference vulnerability in the daemon child process that allows remote attackers to crash the daemon by sending a file list whose first entry is a dot entry not typed as a...
1 affected package
rsync
| Package | 16.04 LTS |
|---|---|
| rsync | Needs evaluation |
rsync 3.0.0 before 3.5.0 contains an out-of-bounds write vulnerability that allows attackers to corrupt memory by triggering HLINK_BUMP processing on file entries with the FLAG_HLINKED flag set while the hard-link preservation...
1 affected package
rsync
| Package | 16.04 LTS |
|---|---|
| rsync | Needs evaluation |
rsync 3.2.3 before 3.5.0 contains an out-of-bounds write in parse_size_arg() where the return value of snprintf() is used directly as an index into a .bss-segment array without bounds checking. When snprintf truncates the...
1 affected package
rsync
| Package | 16.04 LTS |
|---|---|
| rsync | Needs evaluation |
rsync 3.0.1 before 3.5.0 contains an out-of-bounds write vulnerability in the read_args() function that allows a malicious sender to corrupt adjacent heap memory by sending a crafted argument list. When the argument count causes...
1 affected package
rsync
| Package | 16.04 LTS |
|---|---|
| rsync | Needs evaluation |
rsync 3.4.2 before 3.5.0 contains a denial of service vulnerability that allows a remote sender to exhaust system resources by specifying the --zt short alias for --compress-threads, which bypasses the refuse options directive's...
1 affected package
rsync
| Package | 16.04 LTS |
|---|---|
| rsync | Needs evaluation |
rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS certificate validation vulnerability that allows on-path attackers to intercept encrypted sessions by presenting self-signed or...
1 affected package
rsync
| Package | 16.04 LTS |
|---|---|
| rsync | Needs evaluation |
rsync before 3.5.0 contains an algorithmic complexity vulnerability in the hash_search() function that allows a remote attacker to cause a denial of service by delivering a carefully constructed file list. A sender can exploit the...
1 affected package
rsync
| Package | 16.04 LTS |
|---|---|
| rsync | Needs evaluation |
rsync 3.1.0 before 3.5.0 contains an access control bypass vulnerability that allows remote attackers to circumvent hosts deny rules by inducing DNS resolution failures during hostname-based access control evaluation. When a DNS...
1 affected package
rsync
| Package | 16.04 LTS |
|---|---|
| rsync | Needs evaluation |
[GHSA-jv8r-gqr9-68wj: Memory-amplification denial of service via unvalidated DNS header record counts]
1 affected package
c-ares
| Package | 16.04 LTS |
|---|---|
| c-ares | Needs evaluation |