Rsync remote code execution and related vulnerability fixes available

1 · Ubuntu · Jan. 15, 2025, 3:10 a.m.
Summary
Security researchers at Google have uncovered vulnerabilities in the rsync server and client that could allow remote code execution and other malicious activities. The post details specific vulnerabilities (CVE-2024-12084 and CVE-2024-12085) that can lead to remote code execution, as well as how a rogue server could exploit the rsync client to access files and create unsafe symlinks.