Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2022-29154
Description:An issue was discovered in rsync before 3.2.5 that allows malicious remote servers to write arbitrary files inside the directories of connecting peers. The server chooses which files/directories are sent to the client. However, the rsync client performs insufficient validation of file names. A malicious rsync server (or Man-in-The- Middle attacker) can overwrite arbitrary files in the rsync client target directory and subdirectories (for example, overwrite the .ssh/authorized_keys file).
Test IDs: 1.3.6.1.4.1.25623.1.1.10.2022.0302   1.3.6.1.4.1.25623.1.1.4.2022.2959.1   1.3.6.1.4.1.25623.1.1.4.2022.2825.1   1.3.6.1.4.1.25623.1.1.2.2023.1290   1.3.6.1.4.1.25623.1.1.4.2022.2858.1   1.3.6.1.4.1.25623.1.0.884241   1.3.6.1.4.1.25623.1.0.833745   1.3.6.1.4.1.25623.1.1.12.2023.5921.1   1.3.6.1.4.1.25623.1.1.13.2022.227.01   1.3.6.1.4.1.25623.1.1.2.2023.2204   1.3.6.1.4.1.25623.1.1.2.2023.2402   1.3.6.1.4.1.25623.1.1.4.2022.2859.1   1.3.6.1.4.1.25623.1.0.854937   1.3.6.1.4.1.25623.1.1.2.2022.2448   1.3.6.1.4.1.25623.1.1.2.2022.2479   1.3.6.1.4.1.25623.1.0.854903  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2022-29154
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NMBOJ77A7T7PQCARMDUK75TE6LLESZ3O/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YRQAI7H4M4RQZ2IWZUEEXECBE5D56BH2/
https://github.com/WayneD/rsync/tags
http://www.openwall.com/lists/oss-security/2022/08/02/1




© 1998-2025 E-Soft Inc. All rights reserved.