#VU102734 Path traversal in Rsync - CVE-2024-12087
Published: January 14, 2025
Rsync
Samba
Description
The vulnerability allows a remote server to write files to arbitrary locations on the system.
The vulnerability exists due to input validation error when using "--inc-recursive" option. A remote attacker can can trick the victim into connecting to a rouge rsync server and write arbitrary files to arbitrary locations on the client system.