What is Nostr?
Jan Schaumann /
npub1kvy…edh2
2025-01-14 18:26:09

Jan Schaumann on Nostr: 6 new CVEs in "rsync". "In the most severe CVE, an attacker only requires anonymous ...

6 new CVEs in "rsync".

"In the most severe CVE, an attacker only requires anonymous read access to a rsync server, such as a public mirror, to execute arbitrary code on the machine the server is running on."

That would be CVE-2024-12084 (9.8) AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, a heap-based buffer overflow in rsyncd.

https://www.openwall.com/lists/oss-security/2025/01/14/3
Author Public Key
npub1kvy8enal7npw9ct28tc53d4r5fl7q7a3ua3gku22z8jlyec37f3snmedh2