[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

RSYNC - (bulletinoct2017)

ID: oval:org.secpod.oval:def:2101451Date: (C)2020-01-18   (M)2021-09-11
Class: PATCHFamily: unix




The receive_xattr function in xattrs.c in rsync 3.1.2 and 3.1.3-development does not check for a trailing "\0" character in an xattr name, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact by sending crafted data to the daemon.

Platform:
Sun Solaris 11
Product:
network/rsync
Reference:
bulletinoct2017
CVE-2017-16548
CVE    1
CVE-2017-16548
CPE    1
cpe:/o:oracle:solaris:11

© SecPod Technologies