GHSA-ffg2-fr5g-3rxw
CVE Information
With
use chroot = nothe daemon changes directory into the module path using a plainchdir()that followed an attacker-planted parent-component symlink, causing the daemon to serve files from outside the configured module before any transfer began.Fix: confine the module-root chdir through the secure resolver.
Test: daemon-module-chdir-symlink.
Affected: rsync 3.4.3 and earlier; fixed in 3.5.0. (Precise introduced-in ranges being finalised.)