- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4015-1                debian-lts@lists.debian.org
https://www.debian.org/lts/security/                    Thorsten Alteholz
January 14, 2025                              https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : rsync
Version        : 3.2.3-4+deb11u2
CVE ID         : CVE-2024-12085 CVE-2024-12086 CVE-2024-12087
                  CVE-2024-12088 CVE-2024-12747


Several vulnerabilities were discovered in rsync, a fast, versatile,
remote (and local) file-copying tool.

CVE-2024-12085

     Simon Scannell, Pedro Gallegos and Jasiel Spelman reported a flaw in
     the way rsync compares file checksums, allowing a remote attacker to
     trigger an information leak.

CVE-2024-12086

     Simon Scannell, Pedro Gallegos and Jasiel Spelman discovered a flaw
     which would result in a server leaking contents of an arbitrary file
     from the client's machine.

CVE-2024-12087

     Simon Scannell, Pedro Gallegos and Jasiel Spelman reported a path
     traversal vulnerability in the rsync daemon affecting the
     --inc-recursive option, which could allow a server to write files
     outside of the client's intended destination directory.

CVE-2024-12088

     Simon Scannell, Pedro Gallegos and Jasiel Spelman reported that when
     using the --safe-links option, rsync fails to properly verify if a
     symbolic link destination contains another symbolic link with it,
     resulting in path traversal and arbitrary file write outside of the
     desired directory.

CVE-2024-12747

     Aleksei Gorban "loqpa" discovered a race condition when handling
     symbolic links resulting in an information leak which may enable
     escalation of privileges.


For Debian 11 bullseye, these problems have been fixed in version
3.2.3-4+deb11u2.

We recommend that you upgrade your rsync packages.

For the detailed security status of rsync please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/rsync

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Debian LTS: DLA-4015-1: rsync Security Advisory Updates

January 14, 2025
Several vulnerabilities were discovered in rsync, a fast, versatile, remote (and local) file-copying tool

Summary

Several vulnerabilities were discovered in rsync, a fast, versatile,
remote (and local) file-copying tool.

CVE-2024-12085

Simon Scannell, Pedro Gallegos and Jasiel Spelman reported a flaw in
the way rsync compares file checksums, allowing a remote attacker to
trigger an information leak.

CVE-2024-12086

Simon Scannell, Pedro Gallegos and Jasiel Spelman discovered a flaw
which would result in a server leaking contents of an arbitrary file
from the client's machine.

CVE-2024-12087

Simon Scannell, Pedro Gallegos and Jasiel Spelman reported a path
traversal vulnerability in the rsync daemon affecting the
--inc-recursive option, which could allow a server to write files
outside of the client's intended destination directory.

CVE-2024-12088

Simon Scannell, Pedro Gallegos and Jasiel Spelman reported that when
using the --safe-links option, rsync fails to properly verify if a
symbolic link destination contains another symbolic link with it,
...

Read the Full Advisory


Severity
Package : rsync
Version : 3.2.3-4+deb11u2
CVE ID : CVE-2024-12085 CVE-2024-12086 CVE-2024-12087

Related News