• CVE-2024-12086

发布时间: 2025年1月17日

修改时间: 2025年1月17日

概要

A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when files are being copied from a client to a server. During this process, the rsync server will send checksums of local data to the client to compare with in order to determine what data needs to be sent to the server. By sending specially constructed checksum values for arbitrary files, an attacker may be able to reconstruct the data of those files byte-by-byte based on the responses from the client.

CVSS v3 指标

NVD openEuler
Confidentiality High
Attack Vector Network
CVSS评分 N/A 6.1
Attack Complexity High
Privileges Required None
Scope Changed
Integrity None
User Interaction Required
Availability None

安全公告

公告名 概要 发布时间
KylinSec-SA-2025-1139 rsync security update 2025年2月28日
KylinSec-SA-2025-1253 rsync security update 2025年3月6日

影响产品

产品 状态
KY3.4-5A rsync Fixed
KY3.5.3 rsync Fixed
V6 rsync Fixed