CVE-2017-17434: Debian Linux

Critical severity, CVSS 9.8. EPSS: 3.3% chance of exploitation in the next 30 days.

The daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, does not check for fnamecmp filenames in the daemon_filter_list data structure (in the recv_files function in receiver.c) and also does not apply the sanitize_paths protection mechanism to pathnames found in "xname follows" strings (in the read_ndx_and_attrs function in rsync.c), which allows remote attackers to bypass intended access restrictions.

Affected products

  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Samba Rsync: up to and including 3.1.2

Published 2017-12-06. Last modified 2026-06-17.