A flaw was found in rsync. When using the --safe-links option, the rsync client fails to properly verify if a symbolic link destination sent from the server contains another symbolic link within it. This results in a path traversal vulnerability, which may lead to arbitrary file write outside the desired directory.
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.14"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "4.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "6.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "10.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.6"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0_aarch64"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.0_aarch64"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.6_aarch64"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0_s390x"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.0_s390x"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.6_s390x"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0_ppc64le"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.0_ppc64le"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.6_ppc64le"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.6"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.6_ppc64le"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.6"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "24.11"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "20250123"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0-NA"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.0-NA"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "10.0-NA"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-12088.json"