rsync 3.1.1 allows remote attackers to write to arbitrary files via a symlink attack on a file in the synchronization path.
CVSS Details
- CVSS 3.1 Base Score: 6.2
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Rsync | — | Apply Apple macOS Security Update 2020-004 High SierraApply Apple macOS Security Update 2020-004 Mojave | Jul 28, 2020 | Jul 24, 2020 |
| Debian | — | Upgrade rsync | Jul 30, 2024 | Feb 12, 2015 |
| Gentoo Linux | — | Upgrade net-misc/rsync. | Oct 30, 2017 | Feb 12, 2015 |
| Huawei Euleros 2_0_sp2 | — | Upgrade rsync | Sep 16, 2021 | Feb 12, 2015 |
| Huawei Euleros 2_0_sp3 | — | Upgrade rsync | Apr 30, 2021 | Feb 12, 2015 |
| Oracle Solaris | — | Upgrade network/rsync to version 3.1.1-0.175.3.1.0.2.0 on Solaris 11.3 | May 29, 2017 | Feb 12, 2015 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Dec 21, 2015 |
| Suse | — | Upgrade rsync | Dec 18, 2015 | Feb 12, 2015 |
| Ubuntu | — | Upgrade rsync | Feb 2, 2016 | Feb 12, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub