Security Advisories

IAC-2025-0012025-01–16Multiple vulnerabilities in rsync

Severity: Medium
Affected versions: 21.0-p21004, 24.0.0 – 21.0-p21592, 24.0.1
Fixed version: 21.0-p21595, 24.0.2
Related CVEs: CVE-2024-12087, CVE-2024-12088
Updated: 2025-01–22
Multiple vulnerabilities have been found in rsync, but most of them affect only the rsync daemon, which is not in use on the IACBOX.
But the rsync client is also affected if connected to unknown servers that are maybe controlled by an attacker.

Which versions are affected?

All versions up to v21 are affected as they are using rsync. The impact is rated only as MEDIUM as an IACBOX is only connecting to Asteas controlled update servers, so there is no real attack surface, except for a possible local exploitation.
The rsync package is updated anyway to eliminate any possibly left over risk.
This issue is fixed with the current version 21.0-p21595.

Version 24 is not using rsync anymore, but as the binary is installed it get's updated to the latest rsync version 3.4.1 too.
The new rsync version is shipped with version 24.0.2, released on 22 Jan 2025.

For all details please visit: https://kb.cert.org/vuls/id/952657

Privacy settings

We use cookies to provide social media features and to analyze traffic to our website. More information

Accept all
Save & close