CVE-2008-1720
Buffer overflow in rsync 2.6.9 to 3.0.1, with extended attribute (xattr) support enabled, might allow remote attackers to execute arbitrary code via unknown vectors.
Date published : 2008-04-10
http://www.securityfocus.com/bid/28726
http://rsync.samba.org/ftp/rsync/security/rsync-3.0.1-xattr-alloc.diff