The parse_arguments function in options.c in rsyncd in rsync before 3.1.3 does not prevent multiple --protect-args uses, which allows remote attackers to bypass an argument-sanitization protection mechanism.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade rsync | Mar 21, 2018 | Jan 17, 2018 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 17, 2018 |
| Debian | — | Upgrade rsync | Feb 25, 2019 | Jan 17, 2018 |
| Gentoo Linux | — | Upgrade net-misc/rsync. | May 9, 2018 | Jan 17, 2018 |
| Huawei Euleros 2_0_sp1 | — | Upgrade rsync | Feb 13, 2018 | Jan 17, 2018 |
| Huawei Euleros 2_0_sp2 | — | Upgrade rsync | Feb 13, 2018 | Jan 17, 2018 |
| Huawei Euleros 2_0_sp5 | — | Upgrade rsync | Aug 16, 2019 | Jan 17, 2018 |
| Oracle Solaris | — | Upgrade network/rsync to version 3.1.3-11.4.3.0.1.3.0 on Solaris 11.4 | Nov 19, 2018 | Jan 17, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jan 17, 2018 |
| Suse | — | Upgrade rsync | Jan 24, 2018 | Jan 17, 2018 |
| Ubuntu | — | Upgrade rsync | Jan 24, 2018 | Jan 17, 2018 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jan 17, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub