Google Cloud Researchers Uncover Flaws in Rsync File Synchronization Tool
Briefly

"Attackers can take control of a malicious server and read/write arbitrary files of any connected client. Sensitive data, such as SSH keys, can be extracted..."
"In the most severe CVE, an attacker only requires anonymous read access to a Rsync server, such as a public mirror, to execute arbitrary code on the machine the server is running on..."
Read at The Hacker News
[
|
]