Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

RSync Receive_XATTR Integer Overflow Vulnerability

The rsync utility is susceptible to a remote integer-overflow vulnerability. This issue is due to the application's failure to properly ensure that user-supplied input doesn't overflow integer values. This may result in user-supplied data being copied past the end of a memory buffer.

Attackers may exploit this issue to execute arbitrary machine code in the context of the affected application, facilitating in the compromise of affected computers.

Versions of rsync prior to 2.6.8 that have had the 'xattrs.diff' patch applied are vulnerable to this issue.







 

Privacy Statement
Copyright 2009, SecurityFocus