SUSE-SU-2018:0118-1 -- SLES rsyncID: oval:org.secpod.oval:def:89043773 | Date: (C)2021-03-05 (M)2022-08-16 |
Class: PATCH | Family: unix |
This update for rsync fixes several issues. These security issues were fixed: - CVE-2017-17434: The daemon in rsync did not check for fnamecmp filenames in the daemon_filter_list data structure and also did not apply the sanitize_paths protection mechanism to pathnames found in xname follows strings , which allowed remote attackers to bypass intended access restrictions . - CVE-2017-17433: The recv_files function in receiver.c in the daemon in rsync, proceeded with certain file metadata updates before checking for a filename in the daemon_filter_list data structure, which allowed remote attackers to bypass intended access restrictions . - CVE-2017-16548: The receive_xattr function in xattrs.c in rsync did not check for a trailing "\\0" character in an xattr name, which allowed remote attackers to cause a denial of service or possibly have unspecified other impact by sending crafted data to the daemon . This non-security issue was fixed: - Stop file upload after errors like a full disk - Ensure -X flag works even when setting owner/group
Platform: |
SUSE Linux Enterprise Server 12 SP3 |
SUSE Linux Enterprise Server 12 SP2 |