Description
The parse_arguments function in options.c in rsyncd in rsync before 3.1.3 does not prevent multiple --protect-args uses, which allows remote attackers to bypass an argument-sanitization protection mechanism.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1247-1 | rsync security update |
Debian DLA |
DLA-1725-1 | rsync security update |
Debian DLA |
DLA-2833-1 | rsync security update |
EUVD |
EUVD-2018-17533 | The parse_arguments function in options.c in rsyncd in rsync before 3.1.3 does not prevent multiple --protect-args uses, which allows remote attackers to bypass an argument-sanitization protection mechanism. |
Ubuntu USN |
USN-3543-1 | rsync vulnerabilities |
Ubuntu USN |
USN-3543-2 | rsync vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T05:40:51.281Z
Reserved: 2018-01-17T00:00:00.000Z
Link: CVE-2018-5764
No data.
Status : Modified
Published: 2018-01-17T22:29:00.217
Modified: 2024-11-21T04:09:21.117
Link: CVE-2018-5764
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Ubuntu USN