Improper authorization control for web services In rsync
Description
Rsync version 3.4.2 and prior contain an authorization bypass vulnerability in the rsync daemon's hostname-based access control list enforcement when configured with chroot. Attackers can bypass hostname-based deny rules by controlling the PTR record for their source IP address, allowing connections from hostnames that administrators intended to deny when reverse DNS resolution fails and defaults to UNKNOWN.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 12 | 3.2.7-1+deb12u5 | ||
debian 14 | 3.4.3+ds1-1 | ||
debian 13 | 3.4.1+ds1-5+deb13u3 | ||
debian 11 | 3.2.3-4+deb11u4 | ||
alpine v3.20 | 3.4.3-r0 | ||
alpine v3.21 | 3.4.3-r0 | ||
alpine v3.22 | 3.4.3-r0 | ||
alpine v3.23 | 3.4.3-r0 | ||
rpm rhel8 | - | - | |
rpm rhel10 | - | - |
1-10 of 13
10
Aliases
1. 2. 3. 4. 5. 6. 7.