The copy_symlink function in rsnapshot 1.2.0 and 1.1.x before 1.1.7 changes the ownership of files that a symlink points to rather than the symlink itself, which allows local users to obtain access to arbitrary files.
AV:L/AC:L/Au:N/C:P/I:P/A:P
This vulnerability has a 0.36% probability of being exploited in the next 30 days, ranking higher than 27% of all scored CVEs.