Samba Rsync 3.2.4

CPE Details

Samba Rsync 3.2.4
3.2.4
2021-06-04
10h15 +00:00
2021-06-04
12h07 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:samba:rsync:3.2.4:*:*:*:*:*:*:*

Informations

Vendor

samba

Product

rsync

Version

3.2.4

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2022-29154 2022-08-02 12h22 +00:00 An issue was discovered in rsync before 3.2.5 that allows malicious remote servers to write arbitrary files inside the directories of connecting peers. The server chooses which files/directories are sent to the client. However, the rsync client performs insufficient validation of file names. A malicious rsync server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the rsync client target directory and subdirectories (for example, overwrite the .ssh/authorized_keys file).
7.4
High