[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249622

 
 

909

 
 

195549

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SU-2018:0117-1 -- SLES rsync

ID: oval:org.secpod.oval:def:89002142Date: (C)2021-02-26   (M)2022-10-10
Class: PATCHFamily: unix




This update for rsync fixes the following issues: Security issues fixed: - CVE-2017-17434: The daemon in rsync did not check for fnamecmp filenames in the daemon_filter_list data structure and also did not apply the sanitize_paths protection mechanism to pathnames found in quot;xname followsquot; strings , which allowed remote attackers to bypass intended access restrictionsquot; . - CVE-2017-17433: The recv_files function in receiver.c in the daemon in rsync, proceeded with certain file metadata updates before checking for a filename in the daemon_filter_list data structure, which allowed remote attackers to bypass intended access restrictions . - CVE-2017-16548: The receive_xattr function in xattrs.c in rsync did not check for a trailing "\\0" character in an xattr name, which allowed remote attackers to cause a denial of service or possibly have unspecified other impact by sending crafted data to the daemon .

Platform:
SUSE Linux Enterprise Server 11 SP4
Product:
rsync
Reference:
SUSE-SU-2018:0117-1
CVE-2017-16548
CVE-2017-17433
CVE-2017-17434
CVE    3
CVE-2017-16548
CVE-2017-17433
CVE-2017-17434
CPE    2
cpe:/a:rsync:rsync
cpe:/o:suse:suse_linux_enterprise_server:11:sp4

© SecPod Technologies