Security researchers at Google, namely Pedro Gallegos, Simon Scannell, and Jasiel Spelman, identified vulnerabilities in both the rsync server and client. These vulnerabilities range from extremely concerning to just annoying, and are at different stages of being patched. This blog post will be updated as patches are released by us.
The Announcement
The server vulnerabilities (CVE-2024-12084 and CVE-2024-12085) can lead to remote code execution (RCE). On the client side, vulnerabilities allow a malicious server to read arbitrary files (CVE-2024-12086), create unsafe symlinks (CVE-2024-12087), and, under certain conditions, overwrite arbitrary files (CVE-2024-12088). Additionally, during the coordinated response to these issues, Aleksei Gorban reported a sixth vulnerability (CVE-2024-12747) related to how the rsync server manages symlinks.
SOCIAL SHARE CARD GENERATOR