Loading HuntDB...

GHSA-vp2c-23x9-j4wq

GitHub Security Advisory

⚠ Unreviewed CRITICAL Has CVE

Advisory Details

The receive_xattr function in xattrs.c in rsync 3.1.2 and 3.1.3-development does not check for a trailing '\0' character in an xattr name, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact by sending crafted data to the daemon.

Related CVEs

Key Information

GHSA ID
GHSA-vp2c-23x9-j4wq
Published
May 13, 2022 1:27 AM
Last Modified
April 20, 2025 3:48 AM
CVSS Score
9.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: August 31, 2025 6:33 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.