Denial of Service (DoS) The advisory has been revoked - it doesn't affect any version of package rsync  (opens in a new tab)


Threat Intelligence

EPSS
34.02% (99th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CONAN-RSYNC-10078630
  • published8 May 2025
  • disclosed27 Feb 2002
  • creditUnknown

Introduced: 27 Feb 2002

CVE-2002-0048  (opens in a new tab)
CWE-400  (opens in a new tab)

Amendment

This was deemed not a vulnerability.

Overview

Affected versions of this package are vulnerable to Denial of Service (DoS). Multiple signedness errors (mixed signed and unsigned numbers) in the I/O functions of rsync 2.4.6, 2.3.2, and other versions allow remote attackers to cause a denial of service and execute arbitrary code in the rsync client or server.

References