|
Rsync 'xattr' Support Integer Overflow Vulnerability
The rsync utility is prone to a remote integer-overflow vulnerability because the application fails to properly ensure that user-supplied input doesn't overflow integer values. This may result in user-supplied data being copied past the end of a memory buffer. Attackers may exploit this issue to execute arbitrary machine code in the context of the affected application, facilitating in the compromise of affected computers. Versions of rsync between 2.6.9 and 3.0.1 that have 'xattr' support enabled are vulnerable. |
|
|
Privacy Statement |