The parse_arguments function in options.c in rsyncd in rsync before 3.1.3 does not prevent multiple --protect-args uses, which allows remote attackers to bypass an argument-sanitization protection mechanism.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-rsync | Mar 21, 2018 | Jan 17, 2018 | |
| Arch Linux | arch-linux-upgrade-latest | Jul 11, 2025 | Jan 17, 2018 | |
| Debian | debian-upgrade-rsync | Feb 25, 2019 | Jan 17, 2018 | |
| Gentoo Linux | gentoo-linux-upgrade-net-misc-rsync | May 9, 2018 | Jan 17, 2018 | |
| Huawei Euleros 2_0_sp1 | huawei-euleros-2_0_sp1-upgrade-rsync | Feb 13, 2018 | Jan 17, 2018 | |
| Huawei Euleros 2_0_sp2 | huawei-euleros-2_0_sp2-upgrade-rsync | Feb 13, 2018 | Jan 17, 2018 | |
| Huawei Euleros 2_0_sp5 | huawei-euleros-2_0_sp5-upgrade-rsync | Aug 16, 2019 | Jan 17, 2018 | |
| Oracle Solaris | oracle-solaris-11-4-upgrade-network-rsync-3-1-3-11-4-3-0-1-3-0 | Nov 19, 2018 | Jan 17, 2018 | |
| Redhat_linux | no-fix-redhat-rpm-package | Jul 9, 2025 | Jan 17, 2018 | |
| Suse | — | suse-upgrade-rsync | Jan 24, 2018 | Jan 17, 2018 |
| Ubuntu | ubuntu-upgrade-rsync | Jan 24, 2018 | Jan 17, 2018 | |
| Vmware Photon_os | vmware-photon_os_update_tdnf | Jan 20, 2025 | Jan 17, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub