CVE-2026-45232

Published
View on NVD ↗
CVSS v3
3.1
LOW
CVSS v2
N/A
Affected
1
PROJECT

Description

Rsync versions before 3.4.3 contain an off-by-one out-of-bounds stack write vulnerability in the establish_proxy_connection() function in socket.c that allows network attackers to corrupt stack memory by sending a malformed HTTP proxy response. Attackers can exploit this by positioning themselves between the client and proxy or controlling the proxy server to send a response line of 1023 or more bytes without a newline terminator, causing a null byte to be written to an out-of-bounds stack address when the RSYNC_PROXY environment variable is set.

An open source utility that provides fast incremental file transfer. It also has useful features for backup and restore operations among many other use cases.
GitHubGitHub
4.72K