vulnerability

FreeBSD: VID-21f43976-1887-11ed-9911-40b034429ecf (CVE-2022-29154): rsync -- client-side arbitrary file write vulnerability

Severity
9
CVSS
(AV:N/AC:M/Au:N/C:N/I:C/A:C)
Published
Aug 10, 2022
Added
Nov 4, 2022
Modified
Dec 10, 2025

Description

Openwall oss-security reports: We have discovered a critical arbitrary file write vulnerability in the rsync utility that allows malicious remote servers to write arbitrary files inside the directories of connecting peers. The server chooses which files/directories are sent to the client. Due to the insufficient controls inside the do_server_recv function a malicious rysnc server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the rsync client target directory and subdirectories.

Solution

freebsd-upgrade-package-rsync
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.