MidnightBSD

Advisories for lsyncd_project

CVE-2014-8990 HIGH

default-rsyncssh.lua in Lsyncd 2.1.5 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a filename.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-77,

Products Affected

Vendor Product Version
lsyncd_project lsyncd *
fedoraproject fedora 20
debian debian_linux 7.0
fedoraproject fedora 19