rsync-hns-650

Rsync vulnerabilities allow remote code execution on servers, patch quickly!

Teilen:

Six vulnerabilities have been fixed in the newest versions of Rsync (v3.4.0), two of which could be exploited by a malicious client to achieve arbitrary code execution on a machine with a running Rsync server.

“The client requires only anonymous read-access to the server, such as public mirrors. Additionally, attackers can take control of a malicious server and read/write arbitrary files of any connected client. Sensitive data, such as SSH keys, can be extracted, and malicious code can be executed by overwriting files such as ~/.bashrc or ~/.popt,” CERT/CC noted.

About Rsync and the fixed vulnerabilities

Rsync is an open source utility used for synchronizing / transferring files and directories between different systems (computers, servers, storage devices, etc.), and is included by default in base installations of some Linux distributions.

“Rsync can also be used in Daemon mode and is widely used in in public mirrors to synchronize and distribute files efficiently across multiple servers,” CERT/CC added. “Many backup programs, such as Rclone, DeltaCopy, and ChronoSync use Rsync as backend software for file synchronization.”

The fixed vulnerabilities include:

  • CVE-2024-12084CVE-2024-12085 und CVE-2024-12086 are flaws in the Rsync daemon that could be exploited for remote code execution, leaking of stack data, and to read arbitrary files from the client’s machine (when they are being copied from a client to a server)
  • CVE-2024-12087 und CVE-2024-12088 affect the Rsync client and may allow a malicious server to write malicious files to arbitrary locations on connected clients
  • CVE-2024-12747 stems from Rsync improperly handling symbolic links during a race condition and can be used to leak sensitive information to the attacker

They all affect Rsync versions prior to v3.4.0, and CVE-2024-12084 is also present in v3.2.7 and higher. Mitigations for some the first two vulnerabilities are available (see here).

The first five flaws have been reported by Simon Scannell, Pedro Gallegos, and Jasiel Spelman at Google Cloud Vulnerability Research, and the last one by Aleksei Gorban.

What to do?

The Rsync maintainer has released a version with the fixes on Tuesday and users should implement them as soon as possible.

“As Rsync can be distributed bundled, ensure any software that provides such updates is also kept current to address these vulnerabilities,” CERT/CC says.

Updated Rsync packages have already been pushed out for Ubuntu and Debian.

CERT/CC’s list of affected OSes currently includes AlmaLinux OS, Arch Linux, Gentoo Linux, NixOS, Red Hat and SmartOS (i.e., the Triton DataCenter cloud management platform). The list will be updated as more information becomes available.

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
12:48 am, Juli 2, 2025
Wetter-Symbol 21°C
L: 20° | H: 22°
aufgelockerte Bewölkung
Luftfeuchtigkeit: 75 %
Druck: 1015 mb
Wind: 7 mph NNE
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 33%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:48 am
Sonnenuntergang: 9:20 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
20° | 22°°C 0.38 mm 38% 11 mph 79 % 1022 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
14° | 26°°C 0 mm 0% 13 mph 55 % 1028 mb 0 mm/h
Fr. Juli 04 10:00 pm
Wetter-Symbol
15° | 26°°C 0 mm 0% 12 mph 57 % 1028 mb 0 mm/h
Sa. Juli 05 10:00 pm
Wetter-Symbol
15° | 25°°C 1 mm 100% 15 mph 89 % 1022 mb 0 mm/h
So. Juli 06 10:00 pm
Wetter-Symbol
14° | 19°°C 1 mm 100% 13 mph 81 % 1012 mb 0 mm/h
Today 1:00 am
Wetter-Symbol
20° | 21°°C 0 mm 0% 5 mph 75 % 1015 mb 0 mm/h
Today 4:00 am
Wetter-Symbol
18° | 20°°C 0 mm 0% 6 mph 76 % 1015 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
18° | 19°°C 0.2 mm 20% 5 mph 79 % 1016 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
21° | 21°°C 0.2 mm 20% 6 mph 71 % 1017 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
19° | 19°°C 0.38 mm 38% 4 mph 69 % 1018 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
23° | 23°°C 0.35 mm 35% 6 mph 41 % 1019 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
23° | 23°°C 0.01 mm 1% 11 mph 28 % 1020 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
18° | 18°°C 0 mm 0% 10 mph 34 % 1022 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€89,303.86
-1.52%
Ethereum(ETH)
€2,030.01
-3.68%
Fesseln(USDT)
€0.85
-0.01%
XRP(XRP)
€1.84
-3.29%
Solana(SOL)
€124.13
-5.50%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.133204
-4.74%
Shiba Inu(SHIB)
€0.000009
-2.32%
Pepe(PEPE)
€0.000008
-5.46%
Nach oben scrollen