Arbitrary Code Execution The advisory has been revoked - it doesn't affect any version of package rsync  (opens in a new tab)


Threat Intelligence

EPSS
3.35% (88th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CONAN-RSYNC-10078629
  • published8 May 2025
  • disclosed16 Aug 2007
  • creditUnknown

Introduced: 16 Aug 2007

CVE-2007-4091  (opens in a new tab)
CWE-94  (opens in a new tab)

Amendment

This was deemed not a vulnerability.

Overview

Affected versions of this package are vulnerable to Arbitrary Code Execution. Multiple off-by-one errors in the sender.c in rsync 2.6.9 might allow remote attackers to execute arbitrary code via directory names that are not properly handled when calling the f_name function.