Lucene search

K
ubuntuUbuntuUSN-5921-1
HistoryMar 06, 2023 - 12:00 a.m.

rsync vulnerabilities

2023-03-0600:00:00
ubuntu.com
84
rsync
security vulnerability
remote file-copying
ubuntu
privilege escalation

7.4 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H

9.2 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

41.1%

Releases

  • Ubuntu 22.10
  • Ubuntu 22.04 LTS
  • Ubuntu 20.04 LTS
  • Ubuntu 18.04 ESM

Packages

  • rsync - fast, versatile, remote (and local) file-copying tool

Details

Koen van Hove discovered that the rsync client incorrectly validated
filenames returned by servers. If a user or automated system were tricked
into connecting to a malicious server, a remote attacker could use this
issue to write arbitrary files, and possibly escalate privileges.

OSVersionArchitecturePackageVersionFilename
Ubuntu22.10noarchrsync< 3.2.7-0ubuntu0.22.10.1UNKNOWN
Ubuntu22.10noarchrsync-dbgsym< 3.2.7-0ubuntu0.22.10.1UNKNOWN
Ubuntu22.04noarchrsync< 3.2.7-0ubuntu0.22.04.2UNKNOWN
Ubuntu22.04noarchrsync-dbgsym< 3.2.7-0ubuntu0.22.04.2UNKNOWN
Ubuntu20.04noarchrsync< 3.1.3-8ubuntu0.5UNKNOWN
Ubuntu20.04noarchrsync-dbgsym< 3.1.3-8ubuntu0.5UNKNOWN
Ubuntu18.04noarchrsync< 3.1.2-2.1ubuntu1.6UNKNOWN

7.4 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H

9.2 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

41.1%