In Rsync 3.4.0, vulnerabilities that allowed remote code execution on the server and client have been fixed.

The release of the Rsync 3.4.0 file synchronization utility has been published, addressing six vulnerabilities. The combination of vulnerabilities CVE-2024-12084 and CVE-2024-12085 enables a client to execute their code on the server. An anonymous connection to the Rsync server with read access is sufficient for an attack. For instance, attacks can be carried out on mirrors of various distributions and projects offering build downloads via Rsync. This issue also affects various file synchronization and backup applications that use Rsync as a backend, such as Rclone, DeltaCopy, and ChronoSync.

Moreover, exploiting the vulnerability on server the attacker can launch an attack on clients connecting to the server and achieve reading or writing of any files in their system, depending on the permissions of the rsync process. For example, by creating malicious rsync-servers files, SSH keys can be uploaded or code execution can be achieved by overwriting files such as ~/ .bashrc and ~/ .popt.

To simplify the process of upgrading servers to the new Rsync version, the protocol number in the Rsync 3.4.0 release has been raised to 32. You can keep track of updates in distributions on the following pages: Debian, Ubuntu, RHEL, SUSE/openSUSE, Fedora, Arch, FreeBSD.

Identified vulnerabilities:

  • CVE-2024-12084 — out-of-bounds write via the transmission of an incorrect checksum that exceeds 16 bytes.
  • CVE-2024-12085 — leak of uninitialized stack data (one byte at a time) during checksum comparison operations of incorrect size.
  • CVE-2024-12086 — server access to arbitrary file contents from the client's system through the generation of incorrect communication tokens and checksums during file copying from client to server (byte-by-byte determination of contents through checksum guessing).
  • CVE-2024-12087 — directory traversal when using the ‘—inc-recursive’ option (enabled by default for many flags). The vulnerability is caused by inadequate checking of symbolic links and allows writing files outside the specified target directory provided by the client. An attacker-controlled server could exploit this vulnerability to attack the connecting client’s system.
  • CVE-2024-12088 — improper verification of symbolic links pointing to other symbolic links when using the ‘—safe-links’ option. This issue allows for directory traversal and writing data to any file on the system, as permitted by access rights.
  • CVE-2024-12747 — race condition when handling symbolic links, allowing a user to escalate their privileges and gain access to privileged files on the server.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster