rsync-hns-650

Rsync vulnerabilities allow remote code execution on servers, patch quickly!

Teilen:

Six vulnerabilities have been fixed in the newest versions of Rsync (v3.4.0), two of which could be exploited by a malicious client to achieve arbitrary code execution on a machine with a running Rsync server.

“The client requires only anonymous read-access to the server, such as public mirrors. Additionally, attackers can take control of a malicious server and read/write arbitrary files of any connected client. Sensitive data, such as SSH keys, can be extracted, and malicious code can be executed by overwriting files such as ~/.bashrc or ~/.popt,” CERT/CC noted.

About Rsync and the fixed vulnerabilities

Rsync is an open source utility used for synchronizing / transferring files and directories between different systems (computers, servers, storage devices, etc.), and is included by default in base installations of some Linux distributions.

“Rsync can also be used in Daemon mode and is widely used in in public mirrors to synchronize and distribute files efficiently across multiple servers,” CERT/CC added. “Many backup programs, such as Rclone, DeltaCopy, and ChronoSync use Rsync as backend software for file synchronization.”

The fixed vulnerabilities include:

  • CVE-2024-12084CVE-2024-12085 und CVE-2024-12086 are flaws in the Rsync daemon that could be exploited for remote code execution, leaking of stack data, and to read arbitrary files from the client’s machine (when they are being copied from a client to a server)
  • CVE-2024-12087 und CVE-2024-12088 affect the Rsync client and may allow a malicious server to write malicious files to arbitrary locations on connected clients
  • CVE-2024-12747 stems from Rsync improperly handling symbolic links during a race condition and can be used to leak sensitive information to the attacker

They all affect Rsync versions prior to v3.4.0, and CVE-2024-12084 is also present in v3.2.7 and higher. Mitigations for some the first two vulnerabilities are available (see here).

The first five flaws have been reported by Simon Scannell, Pedro Gallegos, and Jasiel Spelman at Google Cloud Vulnerability Research, and the last one by Aleksei Gorban.

What to do?

The Rsync maintainer has released a version with the fixes on Tuesday and users should implement them as soon as possible.

“As Rsync can be distributed bundled, ensure any software that provides such updates is also kept current to address these vulnerabilities,” CERT/CC says.

Updated Rsync packages have already been pushed out for Ubuntu and Debian.

CERT/CC’s list of affected OSes currently includes AlmaLinux OS, Arch Linux, Gentoo Linux, NixOS, Red Hat and SmartOS (i.e., the Triton DataCenter cloud management platform). The list will be updated as more information becomes available.

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
4:46 am, Juli 1, 2025
Wetter-Symbol 22°C
L: 21° | H: 23°
wenige Wolken
Luftfeuchtigkeit: 78 %
Druck: 1014 mb
Wind: 3 mph ENE
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 24%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:47 am
Sonnenuntergang: 9:20 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
21° | 23°°C 0 mm 0% 11 mph 73 % 1015 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
19° | 24°°C 0.2 mm 20% 12 mph 76 % 1024 mb 0 mm/h
Do. Juli 03 10:00 pm
Wetter-Symbol
14° | 26°°C 0 mm 0% 8 mph 52 % 1029 mb 0 mm/h
Fr. Juli 04 10:00 pm
Wetter-Symbol
16° | 29°°C 0 mm 0% 10 mph 48 % 1027 mb 0 mm/h
Sa. Juli 05 10:00 pm
Wetter-Symbol
17° | 22°°C 0.2 mm 20% 13 mph 81 % 1019 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
22° | 22°°C 0 mm 0% 3 mph 73 % 1014 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
26° | 28°°C 0 mm 0% 2 mph 54 % 1014 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
31° | 31°°C 0 mm 0% 7 mph 31 % 1013 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
32° | 32°°C 0 mm 0% 9 mph 25 % 1012 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
28° | 28°°C 0 mm 0% 11 mph 31 % 1013 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
25° | 25°°C 0 mm 0% 8 mph 48 % 1015 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
22° | 22°°C 0 mm 0% 6 mph 65 % 1015 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
19° | 19°°C 0 mm 0% 6 mph 76 % 1016 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€90,947.14
-1.23%
Ethereum(ETH)
€2,109.05
-0.57%
Fesseln(USDT)
€0.85
0.00%
XRP(XRP)
€1.89
1.70%
Solana(SOL)
€130.40
1.25%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.139809
-1.51%
Shiba Inu(SHIB)
€0.000009
-1.70%
Pepe(PEPE)
€0.000008
-3.98%
Nach oben scrollen