Multiple signedness errors (mixed signed and unsigned numbers) in the I/O functions of rsync 2.4.6, 2.3.2, and other versions allow remote attackers to cause a denial of service and execute arbitrary code in the rsync client or server.
2002-02-27T05:00:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 10.0 (HIGH)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | andrew_tridgell | rsync | 2.3.1 | Yes |
| Application | andrew_tridgell | rsync | 2.3.2 | Yes |
| Application | andrew_tridgell | rsync | 2.3.2_1.2 | Yes |
| Application | andrew_tridgell | rsync | 2.3.2_1.2 | Yes |
| Application | andrew_tridgell | rsync | 2.3.2_1.2 | Yes |
| Application | andrew_tridgell | rsync | 2.3.2_1.2 | Yes |
| Application | andrew_tridgell | rsync | 2.3.2_1.2 | Yes |
| Application | andrew_tridgell | rsync | 2.3.2_1.2 | Yes |
| Application | andrew_tridgell | rsync | 2.4.1 | Yes |
| Application | andrew_tridgell | rsync | 2.4.3 | Yes |
| Application | andrew_tridgell | rsync | 2.4.4 | Yes |
| Application | andrew_tridgell | rsync | 2.4.6 | Yes |
| Application | andrew_tridgell | rsync | 2.5.0_1 | Yes |
| Application | andrew_tridgell | rsync | 2.5.1 | Yes |