A heap overflow exists in rsync versions 2.5.6 and below that canbe used by an attacker to run arbitrary code. The bug only affectsrsync in server (daemon) mode and occurs *after* rsync has droppedprivileges.
Under certain conditions, on systems using YP with netgroups in thepassword database, it is possible for the rshd(8) and rexecd(8)daemons to execute the shell from a different user's password entry.