librsync before 1.0.0 uses a truncated MD4 checksum to match blocks, which makes it easier for remote attackers to modify transmitted data via a birthday attack.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade librsync | Jul 30, 2024 | Oct 26, 2015 |
| Freebsd | — | Upgrade librsync | Dec 10, 2025 | Jan 8, 2016 |
| Gentoo Linux | — | Upgrade net-misc/rsync. | Oct 30, 2017 | Oct 26, 2015 |
| Suse | — | Upgrade librsync2Upgrade rsyncUpgrade librsync-devel | Dec 18, 2015 | Oct 26, 2015 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Oct 26, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub