CVE-2024-12084
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2024-12084 is a newly discovered vulnerability affecting the rsync daemon. This issue involves a heap-based buffer overflow, caused by the software's inability to properly manage attacker-controlled checksum lengths. When the maximum digest length (MAX_DIGEST_LEN) surpasses the fixed summary length (SUM_LENGTH) of 16 bytes, an attacker can write beyond the intended bounds of the sum2 buffer. This can potentially lead to arbitrary code execution or denial of service. The vulnerability poses a significant risk and users are encouraged to update their rsync daemons as soon as patches become available.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.