SUSE-SU-2018:0117-1 -- SLES rsyncID: oval:org.secpod.oval:def:89002142 | Date: (C)2021-02-26 (M)2022-10-10 |
Class: PATCH | Family: unix |
This update for rsync fixes the following issues: Security issues fixed: - CVE-2017-17434: The daemon in rsync did not check for fnamecmp filenames in the daemon_filter_list data structure and also did not apply the sanitize_paths protection mechanism to pathnames found in quot;xname followsquot; strings , which allowed remote attackers to bypass intended access restrictionsquot; . - CVE-2017-17433: The recv_files function in receiver.c in the daemon in rsync, proceeded with certain file metadata updates before checking for a filename in the daemon_filter_list data structure, which allowed remote attackers to bypass intended access restrictions . - CVE-2017-16548: The receive_xattr function in xattrs.c in rsync did not check for a trailing "\\0" character in an xattr name, which allowed remote attackers to cause a denial of service or possibly have unspecified other impact by sending crafted data to the daemon .
Platform: |
SUSE Linux Enterprise Server 11 SP4 |