Rsync是RsyncProject开源的一款快速且用途广泛的文件复制工具。用于远程文件和本地文件。 Rsync 3.4.2及之前版本存在安全漏洞,该漏洞源于基于主机名的访问控制列表在配置chroot时存在授权绕过,攻击者可通过控制PTR记录绕过基于主机名的拒绝规则。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| RsyncProject | rsync | < 3.4.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| RsyncProject | rsync | 0 ~ 3.4.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-43618 | 8.1 HIGH | Rsync < 3.4.3 Integer Overflow Information Disclosure |
| CVE-2026-29518 | 7.0 HIGH | Rsync < 3.4.3 TOCTOU Race Condition Allows Symlink-Based Arbitrary File Write |
| CVE-2026-43620 | 6.5 MEDIUM | Rsync < 3.4.3 Out-of-Bounds Array Read via recv_files() |
| CVE-2026-43619 | 6.3 MEDIUM | Rsync < 3.4.3 Symlink Race Condition via Path-Based Syscalls |
| CVE-2026-45232 | 3.1 LOW | Rsync < 3.4.3 Off-by-One Stack Write via HTTP Proxy |
No comments yet