Loading vulnerability details…
CVSS v3.1
N/A
EPSS
34.02%
Published
Feb 27, 2002
Modified
Jun 16, 2026
Public PoC / Exploit (4)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
Multiple signedness errors (mixed signed and unsigned numbers) in the I/O functions of rsync 2.4.6, 2.3.2, and other versions allow remote attackers to cause a denial of service and execute arbitrary code in the rsync client or server.
Affected Products (14)
References (20)