7.5
CVSSv2

CVE-2017-15994

Published: 29/10/2017 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

rsync 3.1.3-development prior to 2017-10-24 mishandles archaic checksums, which makes it easier for remote malicious users to bypass intended access restrictions. NOTE: the rsync development branch has significant use beyond the rsync developers, e.g., the code has been copied for use in various GitHub projects.

Vulnerable Product Search on Vulmon Subscribe to Product

samba rsync

Vendor Advisories

rsync 313-development before 2017-10-24 mishandles archaic checksums, which makes it easier for remote attackers to bypass intended access restrictions NOTE: the rsync development branch has significant use beyond the rsync developers, eg, the code has been copied for use in various GitHub projects ...
rsync 313-development before 2017-10-24, as used in the xlucas svfs rsync fork and other products, mishandles archaic checksums, which makes it easier for remote attackers to bypass intended access restrictions ...