Remote Access Vulnerability in rsync Product by Samba
CVE-2017-15994

9.8CRITICAL

Key Information:

Vendor

Samba

Status
Vendor
CVE Published:
29 October 2017

What is CVE-2017-15994?

In versions of rsync prior to October 24, 2017, malformed archaic checksums can be exploited by remote attackers to bypass security mechanisms designed to restrict access. This vulnerability affects not only the rsync software itself but also extends to various projects that utilize this codebase, emphasizing the need for comprehensive updates and security measures.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.