Multiple off-by-one errors in the sender.c in rsync 2.6.9 might allow remote attackers to execute arbitrary code via directory names that are not properly handled when calling the f_name function.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade rsync | Jul 30, 2024 | Aug 16, 2007 |
| Freebsd | — | Upgrade rsync | Dec 10, 2025 | Aug 21, 2007 |
| Gentoo Linux | — | Upgrade net-misc/rsync. | Oct 30, 2017 | Aug 15, 2007 |
| Suse | — | Upgrade rsync | Feb 17, 2015 | Jul 9, 2013 |
| Ubuntu | — | Upgrade rsync | Nov 8, 2024 | Aug 16, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub