It was discovered that rsync incorrectly handled invalid filenames. A malicious server could use this issue to write files outside of the intended destination directory.
{ "binaries": [ { "binary_version": "3.1.0-2ubuntu0.2", "binary_name": "rsync" } ], "availability": "No subscription required" }
{ "cves": [ { "severity": [ { "score": "medium", "type": "Ubuntu" } ], "id": "CVE-2014-9512" } ], "ecosystem": "Ubuntu:14.04:LTS" }