logo

Six vulnerabilities in ubiquitous rsync tool announced and fixed in a day

ID: 059d158e-b0e3-56de-9165-0ccf466fff5f

STIX ID: report--059d158e-b0e3-56de-9165-0ccf466fff5f

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2025-01-17

Date Updated: 2026-04-26

Author: Liam Proven

...
...

The article describes six security flaws in rsync — including a critical heap-buffer-overflow (CVSS 9.8) and several other issues (information leak, path traversal, symlink race) affecting versions since 3.2.7 — with rsync 3.4.0/3.4.1 released to fix them; while the scale is large (reports of ~600k exposed servers), vendors rapidly issued updates and there are no confirmed active exploits in the wild.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.