Rsync是RsyncProject开源的一款快速且用途广泛的文件复制工具。用于远程文件和本地文件。 Rsync 3.4.3之前版本存在安全漏洞,该漏洞源于establish_proxy_connection函数中存在差一越界栈写入,网络攻击者可通过发送畸形HTTP代理响应破坏栈内存。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| RsyncProject | rsync | < 3.4.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| RsyncProject | rsync | 0 ~ 3.4.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-43618 | 8.1 HIGH | Rsync < 3.4.3 Integer Overflow Information Disclosure |
| CVE-2026-29518 | 7.0 HIGH | Rsync < 3.4.3 TOCTOU Race Condition Allows Symlink-Based Arbitrary File Write |
| CVE-2026-43620 | 6.5 MEDIUM | Rsync < 3.4.3 Out-of-Bounds Array Read via recv_files() |
| CVE-2026-43619 | 6.3 MEDIUM | Rsync < 3.4.3 Symlink Race Condition via Path-Based Syscalls |
| CVE-2026-43617 | 4.8 MEDIUM | Rsync < 3.4.3 Authorization Bypass via Hostname Resolution |
No comments yet