PT-2017-4062 · Rsync+3 · Rsync+3

Publicado

2017-10-31

·

Atualizado

2025-01-13

·

CVE-2017-16548

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions rsync versions 3.1.2 through 3.1.3-development
Description The issue is related to the receive xattr function in xattrs.c, which lacks a check for a trailing '0' character in an xattr name. This can be exploited by a remote attacker to potentially access confidential data, compromise data integrity, and cause a denial of service, including a heap-based buffer over-read and application crash, by sending crafted data to the daemon.
Recommendations For rsync versions 3.1.2 through 3.1.3-development, consider disabling the receive xattr function until a patch is available to prevent potential exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-1219
BDU:2021-01395
CVE-2017-16548
DLA-1218-1
DSA-4068-1
MGASA-2017-0459
OPENSUSE-SU-2024:11308-1
ROSA-SA-2025-2553
SUSE-SU-2018:0117-1
SUSE-SU-2018:0118-1
SUSE-SU-2018_0117-1
SUSE-SU-2018_0118-1
USN-3543-1
USN-3543-2

Produtos afetados

Alt Linux
Suse
Ubuntu
Rsync