[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2022-1873 --- rsync

ID: oval:org.secpod.oval:def:1701055Date: (C)2022-11-10   (M)2023-12-07
Class: PATCHFamily: unix




A flaw was found in rsync that is triggered by a victim rsync user/client connecting to a malicious rsync server. The server can copy and overwrite arbitrary files in the client's rsync target directory and subdirectories. This flaw allows a malicious server, or in some cases, another attacker who performs a man-in-the-middle attack, to potentially overwrite sensitive files on the client machine, resulting in further exploitation

Platform:
Amazon Linux 2
Product:
rsync
Reference:
ALAS2-2022-1873
CVE-2022-29154
CVE    1
CVE-2022-29154

© SecPod Technologies