CVE-2018-5764 PUBLISHED

The parse_arguments function in options.c in rsyncd in rsync before 3.1.3 does not prevent multiple --protect-args uses, which allows remote attackers to bypass an argument-sanitization protection mechanism.

EPSS 7.67% · 91.8th percentile

Risk Scores

EPSS Score
7.67%
91.8th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSrsync0, 3.0.9-4ubuntu1, 3.1.0-2
Ubuntu:16.04:LTSrsync0, 3.1.1-3, 3.1.1-3ubuntu1

Timeline

References

Open in Interactive Console →