First published: Wed Dec 18 2024(Updated: )
This vulnerability stems from a race condition in rsync's handling of symbolic links. By exploiting timing differences, an attacker can bypass the expected behavior of skipping symbolic links during file synchronization. This flaw becomes critical in scenarios where rsync runs with elevated privileges, as it can inadvertently expose sensitive files to unprivileged users, potentially leading to privilege escalation.
Affected Software | Affected Version | How to fix |
---|---|---|
Samba |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.