Six vulnerabilities discovered in rsync
Nick Taitannounced on theoss-security mailing list thatrsync, the widely used file transfer program, had a number of serious vulnerabilities.Users can mitigate all six vulnerabilities by upgrading toversion 3.4.0, which was released on January 14. While all users should upgrade, servers that use rsyncd areespecially impacted:
In the most severe CVE, an attacker only requiresanonymous read access to a rsync server, such as a public mirror, toexecute arbitrary code on the machine the server is running on.