CVE-2024-12747 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

A flaw was found in rsync. This vulnerability arises from a race condition during rsync's handling of symbolic links. Rsync's default behavior when encountering…
Medium CVSS: 5.6

CVE-2024-12747

A flaw was found in rsync. This vulnerability arises from a race condition during rsync's handling of symbolic links. Rsync's default behavior when encountering symbolic links is to skip them. If an attacker replaced a regular file with a symbolic link at the right time, it was possible to bypass the default behavior and traverse symbolic links. Depending on the privileges of the rsync process, an attacker could leak sensitive information, potentially leading to privilege escalation.
Vendor
-
Product
-
CWE
CWE-362
Yayın Tarihi
2025-01-14 18:15:25
Güncelleme
2025-11-03 22:16:39
Source Identifier
secalert@redhat.com
KEV Date Added
-

Kategoriler

Referanslar