Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

rsync Signed Array Index Remote Code Execution Vulnerability

Solution:
rsync 2.5.2 is no longer vulnerable to this issue.

There have been some reports that the provided RedHat and Debian updates cause problems. Please refer to Bugzilla bug 58874 in the references section for details and a proposed solution.

HP has published an advisory stating that the fixes for Red Hat Linux should be applied to HP Secure OS software for Linux. The Red Hat fixes are linked to in the solutions section.

RedHat has released an updated advisory and fixes, which are reported to solve the above issues.

Vendor patches:


rsync rsync 2.3.1

rsync rsync 2.3.2 -1.2 ARM

rsync rsync 2.3.2 -1.2 sparc

rsync rsync 2.3.2 -1.2 m68k

rsync rsync 2.3.2 -1.2 intel

rsync rsync 2.3.2 -1.2 alpha

rsync rsync 2.3.2

rsync rsync 2.3.2 -1.2 PPC

rsync rsync 2.4.1

rsync rsync 2.4.3

rsync rsync 2.4.4

rsync rsync 2.4.6

rsync rsync 2.4.8

rsync rsync 2.5.1







 

Privacy Statement
Copyright 2008, SecurityFocus