In Rsync 3.4.0, vulnerabilities that allowed remote code execution on the server and client have been fixed.
The release of the Rsync file synchronization utility version 3.4.0 has been announced, which fixes six vulnerabilities. A combination of vulnerabilities CVE-2024-12084 and CVE-2024-12085 allows a client to execute their code on the server. An anonymous connection to the Rsync server with read access is sufficient for an attack. For example, an attack could be carried out on mirrors of various distributions and projects that provide the possibility to download builds through […]
