Direct Vulnerabilities

Known vulnerabilities in the rsync package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • H
Improper Certificate Validation

*
  • H
Incorrect Calculation of Buffer Size

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • M
Integer Overflow or Wraparound

*
  • H
Out-of-bounds Write

*
  • H
Out-of-bounds Write

*
  • H
Algorithmic Complexity

*
  • M
Link Following

*
  • H
Link Following

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • M
Improper Validation of Array Index

*
  • H
OS Command Injection

*
  • M
CRLF Injection

*
  • H
Link Following

*
  • H
Symlink Following

*
  • M
Link Following

*
  • H
Link Following

*
  • H
Incorrect Authorization

*
  • H
Out-of-bounds Write

*
  • M
Use of Uninitialized Resource

*
  • M
Incorrect Type Conversion or Cast

*
  • M
Link Following

*
  • M
Link Following

*
  • H
Link Following

*
  • C
Authentication Bypass

*
  • H
Link Following

*
  • H
Link Following

*
  • H
Directory Traversal

*
  • H
Not Failing Securely ('Failing Open')

*
  • M
Link Following

*
  • M
Improper Validation of Specified Quantity in Input

*
  • H
Reliance on Untrusted Inputs in a Security Decision

*
  • M
Incorrect Authorization

*
  • H
Out-of-bounds Read

<3.2.3-4+deb11u4
  • M
Authentication Bypass

<3.2.3-4+deb11u4
  • L
Off-by-one Error

*
  • M
Link Following

<3.2.3-4+deb11u4
  • H
Time-of-check Time-of-use (TOCTOU)

<3.2.3-4+deb11u4
  • M
Out-of-bounds Read

<3.2.3-4+deb11u4
  • H
Improper Handling of Length Parameter Inconsistency

<3.2.3-4+deb11u4
  • L
CVE-2025-10158

<3.2.3-4+deb11u4
  • H
Directory Traversal

<3.2.3-4+deb11u2
  • H
Use of Uninitialized Resource

<3.2.3-4+deb11u2
  • M
Race Condition

<3.2.3-4+deb11u2
  • M
Detection of Error Condition Without Action

<3.2.3-4+deb11u2
  • H
Directory Traversal

<3.2.3-4+deb11u2
  • L
Improper Input Validation

*
  • H
Improper Validation of Certificate with Host Mismatch

<3.2.3-3
  • H
CVE-2018-5764

<3.1.2-2.2
  • L
Missing Authorization

<3.1.2-2.1
  • C
CVE-2017-17434

<3.1.2-2.1
  • C
Out-of-bounds Read

<3.1.2-2.1
  • C
Numeric Errors

<3.1.3-6
  • H
Numeric Errors

<3.1.3-6
  • C
Numeric Errors

<3.1.3-6
  • H
Numeric Errors

<3.1.3-6
  • L
Link Following

<3.1.1-3
  • H
Improper Input Validation

<3.1.0-3
  • L
Out-of-Bounds

<3.0.8
  • H
Out-of-Bounds

<3.0.2-1
  • L
Configuration

<2.6.9-6
  • L
Access Restriction Bypass

<2.6.9-6
  • M
CVE-2007-4091

<2.6.9-5
  • H
CVE-2006-2083

<2.6.8-1
  • M
CVE-2004-0792

<2.6.2-3
  • M
CVE-2004-0426

<2.6.1-1
  • M
CVE-2004-2093

<2.6.1-1
  • H
CVE-2003-0962

<2.5.6-1.1