RSync Receive_XATTR Integer Overflow Vulnerability
BID:17788
Info
RSync Receive_XATTR Integer Overflow Vulnerability
| Bugtraq ID: | 17788 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-2083 |
| Remote: | Yes |
| Local: | No |
| Published: | May 02 2006 12:00AM |
| Updated: | May 08 2006 05:14PM |
| Credit: | This issue was disclosed by the vendor. |
| Vulnerable: |
Trustix Secure Linux 3.0 Trustix Secure Linux 2.2 Trustix Secure Enterprise Linux 2.0 rsync rsync 2.6.7 rsync rsync 2.6.6 rsync rsync 2.6.5 rsync rsync 2.6.5 rsync rsync 2.6.2 rsync rsync 2.6.1 rsync rsync 2.6 rsync rsync 2.5.7 rsync rsync 2.5.6 rsync rsync 2.5.5 rsync rsync 2.5.4 rsync rsync 2.5.3 rsync rsync 2.5.2 rsync rsync 2.5.1 rsync rsync 2.5 .0 rsync rsync 2.4.8 rsync rsync 2.4.6 rsync rsync 2.4.5 rsync rsync 2.4.4 rsync rsync 2.4.3 rsync rsync 2.4.1 rsync rsync 2.4 .0 rsync rsync 2.3.2 -1.3 rsync rsync 2.3.2 -1.2 sparc rsync rsync 2.3.2 -1.2 PPC rsync rsync 2.3.2 -1.2 m68k rsync rsync 2.3.2 -1.2 intel rsync rsync 2.3.2 -1.2 ARM rsync rsync 2.3.2 -1.2 alpha rsync rsync 2.3.2 rsync rsync 2.3.1 |
| Not Vulnerable: |
rsync rsync 2.6.8 |
Discussion
RSync Receive_XATTR Integer Overflow Vulnerability
The rsync utility is susceptible to a remote integer-overflow vulnerability. This issue is due to the application's failure to properly ensure that user-supplied input doesn't overflow integer values. This may result in user-supplied data being copied past the end of a memory buffer.
Attackers may exploit this issue to execute arbitrary machine code in the context of the affected application, facilitating in the compromise of affected computers.
Versions of rsync prior to 2.6.8 that have had the 'xattrs.diff' patch applied are vulnerable to this issue.
The rsync utility is susceptible to a remote integer-overflow vulnerability. This issue is due to the application's failure to properly ensure that user-supplied input doesn't overflow integer values. This may result in user-supplied data being copied past the end of a memory buffer.
Attackers may exploit this issue to execute arbitrary machine code in the context of the affected application, facilitating in the compromise of affected computers.
Versions of rsync prior to 2.6.8 that have had the 'xattrs.diff' patch applied are vulnerable to this issue.
Exploit / POC
RSync Receive_XATTR Integer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution / Fix
RSync Receive_XATTR Integer Overflow Vulnerability
Solution:
The vendor has released version 2.6.8 of rsync, which includes a fixed version of the 'xattrs.diff' patch to address this issue.
Please see the referenced vendor advisories for further information.
rsync rsync 2.3.1
rsync rsync 2.3.2 -1.2 sparc
rsync rsync 2.3.2
rsync rsync 2.3.2 -1.2 ARM
rsync rsync 2.3.2 -1.2 m68k
rsync rsync 2.3.2 -1.3
rsync rsync 2.3.2 -1.2 alpha
rsync rsync 2.3.2 -1.2 PPC
rsync rsync 2.3.2 -1.2 intel
rsync rsync 2.4 .0
rsync rsync 2.4.1
rsync rsync 2.4.3
rsync rsync 2.4.4
rsync rsync 2.4.5
rsync rsync 2.4.6
rsync rsync 2.4.8
rsync rsync 2.5 .0
rsync rsync 2.5.1
rsync rsync 2.5.2
rsync rsync 2.5.3
rsync rsync 2.5.4
rsync rsync 2.5.5
rsync rsync 2.5.6
rsync rsync 2.5.7
rsync rsync 2.6
rsync rsync 2.6.1
rsync rsync 2.6.2
rsync rsync 2.6.5
rsync rsync 2.6.5
rsync rsync 2.6.6
rsync rsync 2.6.7
Solution:
The vendor has released version 2.6.8 of rsync, which includes a fixed version of the 'xattrs.diff' patch to address this issue.
Please see the referenced vendor advisories for further information.
rsync rsync 2.3.1
-
rsync rsync-2.6.8.tar.gz
http://samba.anu.edu.au/ftp/rsync/rsync-2.6.8.tar.gz
rsync rsync 2.3.2 -1.2 sparc
-
rsync rsync-2.6.8.tar.gz
http://samba.anu.edu.au/ftp/rsync/rsync-2.6.8.tar.gz
rsync rsync 2.3.2
-
rsync rsync-2.6.8.tar.gz
http://samba.anu.edu.au/ftp/rsync/rsync-2.6.8.tar.gz
rsync rsync 2.3.2 -1.2 ARM
-
rsync rsync-2.6.8.tar.gz
http://samba.anu.edu.au/ftp/rsync/rsync-2.6.8.tar.gz
rsync rsync 2.3.2 -1.2 m68k
-
rsync rsync-2.6.8.tar.gz
http://samba.anu.edu.au/ftp/rsync/rsync-2.6.8.tar.gz
rsync rsync 2.3.2 -1.3
-
rsync rsync-2.6.8.tar.gz
http://samba.anu.edu.au/ftp/rsync/rsync-2.6.8.tar.gz
rsync rsync 2.3.2 -1.2 alpha
-
rsync rsync-2.6.8.tar.gz
http://samba.anu.edu.au/ftp/rsync/rsync-2.6.8.tar.gz
rsync rsync 2.3.2 -1.2 PPC
-
rsync rsync-2.6.8.tar.gz
http://samba.anu.edu.au/ftp/rsync/rsync-2.6.8.tar.gz
rsync rsync 2.3.2 -1.2 intel
-
rsync rsync-2.6.8.tar.gz
http://samba.anu.edu.au/ftp/rsync/rsync-2.6.8.tar.gz
rsync rsync 2.4 .0
-
rsync rsync-2.6.8.tar.gz
http://samba.anu.edu.au/ftp/rsync/rsync-2.6.8.tar.gz
rsync rsync 2.4.1
-
rsync rsync-2.6.8.tar.gz
http://samba.anu.edu.au/ftp/rsync/rsync-2.6.8.tar.gz
rsync rsync 2.4.3
-
rsync rsync-2.6.8.tar.gz
http://samba.anu.edu.au/ftp/rsync/rsync-2.6.8.tar.gz
rsync rsync 2.4.4
-
rsync rsync-2.6.8.tar.gz
http://samba.anu.edu.au/ftp/rsync/rsync-2.6.8.tar.gz
rsync rsync 2.4.5
-
rsync rsync-2.6.8.tar.gz
http://samba.anu.edu.au/ftp/rsync/rsync-2.6.8.tar.gz
rsync rsync 2.4.6
-
rsync rsync-2.6.8.tar.gz
http://samba.anu.edu.au/ftp/rsync/rsync-2.6.8.tar.gz
rsync rsync 2.4.8
-
rsync rsync-2.6.8.tar.gz
http://samba.anu.edu.au/ftp/rsync/rsync-2.6.8.tar.gz
rsync rsync 2.5 .0
-
rsync rsync-2.6.8.tar.gz
http://samba.anu.edu.au/ftp/rsync/rsync-2.6.8.tar.gz
rsync rsync 2.5.1
-
rsync rsync-2.6.8.tar.gz
http://samba.anu.edu.au/ftp/rsync/rsync-2.6.8.tar.gz
rsync rsync 2.5.2
-
rsync rsync-2.6.8.tar.gz
http://samba.anu.edu.au/ftp/rsync/rsync-2.6.8.tar.gz
rsync rsync 2.5.3
-
rsync rsync-2.6.8.tar.gz
http://samba.anu.edu.au/ftp/rsync/rsync-2.6.8.tar.gz
rsync rsync 2.5.4
-
rsync rsync-2.6.8.tar.gz
http://samba.anu.edu.au/ftp/rsync/rsync-2.6.8.tar.gz
rsync rsync 2.5.5
-
rsync rsync-2.6.8.tar.gz
http://samba.anu.edu.au/ftp/rsync/rsync-2.6.8.tar.gz
rsync rsync 2.5.6
-
rsync rsync-2.6.8.tar.gz
http://samba.anu.edu.au/ftp/rsync/rsync-2.6.8.tar.gz
rsync rsync 2.5.7
-
rsync rsync-2.6.8.tar.gz
http://samba.anu.edu.au/ftp/rsync/rsync-2.6.8.tar.gz
rsync rsync 2.6
-
rsync rsync-2.6.8.tar.gz
http://samba.anu.edu.au/ftp/rsync/rsync-2.6.8.tar.gz
rsync rsync 2.6.1
-
rsync rsync-2.6.8.tar.gz
http://samba.anu.edu.au/ftp/rsync/rsync-2.6.8.tar.gz
rsync rsync 2.6.2
-
rsync rsync-2.6.8.tar.gz
http://samba.anu.edu.au/ftp/rsync/rsync-2.6.8.tar.gz
rsync rsync 2.6.5
-
rsync rsync-2.6.8.tar.gz
http://samba.anu.edu.au/ftp/rsync/rsync-2.6.8.tar.gz
rsync rsync 2.6.5
-
rsync rsync-2.6.8.tar.gz
http://samba.anu.edu.au/ftp/rsync/rsync-2.6.8.tar.gz
rsync rsync 2.6.6
-
rsync rsync-2.6.8.tar.gz
http://samba.anu.edu.au/ftp/rsync/rsync-2.6.8.tar.gz
rsync rsync 2.6.7
-
rsync rsync-2.6.8.tar.gz
http://samba.anu.edu.au/ftp/rsync/rsync-2.6.8.tar.gz
References
RSync Receive_XATTR Integer Overflow Vulnerability
References:
References:
- NEWS for rsync 2.6.8 (22 Apr 2006) (rsync)
- rsync Homepage (rsync)