Search CVE reports


Toggle filters

31 – 40 of 41 results


CVE-2014-8242

Low priority
Vulnerable

librsync before 1.0.0 uses a truncated MD4 checksum to match blocks, which makes it easier for remote attackers to modify transmitted data via a birthday attack.

1 affected package

librsync

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
librsync Not affected Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2014-9512

Medium priority

Some fixes available 4 of 6

rsync 3.1.1 allows remote attackers to write to arbitrary files via a symlink attack on a file in the synchronization path.

1 affected package

rsync

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rsync
Show less packages

CVE-2014-2855

Medium priority
Fixed

The check_secret function in authenticate.c in rsync 3.1.0 and earlier allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a user name which does not exist in the secrets file.

1 affected package

rsync

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rsync
Show less packages

CVE-2011-1097

Medium priority
Fixed

rsync 3.x before 3.0.8, when certain recursion, deletion, and ownership options are used, allows remote rsync servers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code...

1 affected package

rsync

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rsync
Show less packages

CVE-2008-5150

Negligible priority
Vulnerable

sample.sh in maildirsync 1.1 allows local users to append data to arbitrary files via a symlink attack on a /tmp/maildirsync-*.#####.log temporary file.

1 affected package

maildirsync

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
maildirsync Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2008-1720

Medium priority
Fixed

Buffer overflow in rsync 2.6.9 to 3.0.1, with extended attribute (xattr) support enabled, might allow remote attackers to execute arbitrary code via unknown vectors.

1 affected package

rsync

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rsync
Show less packages

CVE-2007-6200

Low priority
Ignored

Unspecified vulnerability in rsync before 3.0.0pre6, when running a writable rsync daemon, allows remote attackers to bypass exclude, exclude_from, and filter and read or write hidden files via (1) symlink, (2) partial-dir, (3)...

1 affected package

rsync

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rsync
Show less packages

CVE-2007-6199

Low priority
Ignored

rsync before 3.0.0pre6, when running a writable rsync daemon that is not using chroot, allows remote attackers to access restricted files via unknown vectors that cause rsync to create a symlink that points outside of the module's...

1 affected package

rsync

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rsync
Show less packages

CVE-2007-4091

Medium priority
Fixed

Multiple off-by-one errors in the sender.c in rsync 2.6.9 might allow remote attackers to execute arbitrary code via directory names that are not properly handled when calling the f_name function.

1 affected package

rsync

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rsync
Show less packages

CVE-2006-2083

Medium priority
Fixed

Integer overflow in the receive_xattr function in the extended attributes patch (xattr.c) for rsync before 2.6.8 might allow attackers to execute arbitrary code via crafted extended attributes that trigger a buffer overflow.

1 affected package

rsync

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rsync
Show less packages