Rsync 'xattr' Support Integer Overflow Vulnerability
BID:28726
Info
Rsync 'xattr' Support Integer Overflow Vulnerability
| Bugtraq ID: | 28726 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-1720 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 10 2008 12:00AM |
| Updated: | Apr 13 2015 09:51PM |
| Credit: | Sebastian Krahmer |
| Vulnerable: |
Ubuntu Ubuntu Linux 7.10 sparc Ubuntu Ubuntu Linux 7.10 powerpc Ubuntu Ubuntu Linux 7.10 i386 Ubuntu Ubuntu Linux 7.10 amd64 S.u.S.E. openSUSE 10.3 rsync rsync 3.0.1 rsync rsync 3.0 rsync rsync 2.6.9 rsync rsync 3.0.0pre6 Redhat Fedora 7 HP Insight Control for Linux (ICE-LX) 2.10 Gentoo Linux Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 cwRsync cwRsync 2.1.2 cwRsync cwRsync 2.1.1 cwRsync cwRsync 2.1 |
| Not Vulnerable: |
rsync rsync 3.0.2 HP Insight Control 6.0 cwRsync cwRsync 2.1.3 |
Discussion
Rsync 'xattr' Support Integer Overflow Vulnerability
The rsync utility is prone to a remote integer-overflow vulnerability because the application fails to properly ensure that user-supplied input doesn't overflow integer values. This may result in user-supplied data being copied past the end of a memory buffer.
Attackers may exploit this issue to execute arbitrary machine code in the context of the affected application, facilitating in the compromise of affected computers.
Versions of rsync between 2.6.9 and 3.0.1 that have 'xattr' support enabled are vulnerable.
The rsync utility is prone to a remote integer-overflow vulnerability because the application fails to properly ensure that user-supplied input doesn't overflow integer values. This may result in user-supplied data being copied past the end of a memory buffer.
Attackers may exploit this issue to execute arbitrary machine code in the context of the affected application, facilitating in the compromise of affected computers.
Versions of rsync between 2.6.9 and 3.0.1 that have 'xattr' support enabled are vulnerable.
Exploit / POC
Rsync 'xattr' Support Integer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Rsync 'xattr' Support Integer Overflow Vulnerability
Solution:
This issue has been fixed in rsync 3.0.2. Please see the references for more information.
rsync rsync 3.0.0pre6
cwRsync cwRsync 2.1
cwRsync cwRsync 2.1.1
cwRsync cwRsync 2.1.2
rsync rsync 2.6.9
rsync rsync 3.0
rsync rsync 3.0.1
Solution:
This issue has been fixed in rsync 3.0.2. Please see the references for more information.
rsync rsync 3.0.0pre6
-
rsync rsync-3.0.1-xattr-alloc.diff
http://rsync.samba.org/ftp/rsync/security/rsync-3.0.1-xattr-alloc.diff
cwRsync cwRsync 2.1
-
cwRsync cwRsync 2.1.3
http://www.itefix.no/phpws/index.php?module=linkman&LMN_op=visitLink&L MN_id=1
cwRsync cwRsync 2.1.1
-
cwRsync cwRsync 2.1.3
http://www.itefix.no/phpws/index.php?module=linkman&LMN_op=visitLink&L MN_id=1
cwRsync cwRsync 2.1.2
-
cwRsync cwRsync 2.1.3
http://www.itefix.no/phpws/index.php?module=linkman&LMN_op=visitLink&L MN_id=1
rsync rsync 2.6.9
-
rsync rsync-3.0.1-xattr-alloc.diff
http://rsync.samba.org/ftp/rsync/security/rsync-3.0.1-xattr-alloc.diff -
Ubuntu rsync_2.6.9-3ubuntu1.2_amd64.deb
amd64 architecture (Athlon64, Opteron, EM64T Xeon) - Ubuntu 7.04
http://security.ubuntu.com/ubuntu/pool/main/r/rsync/rsync_2.6.9-3ubunt u1.2_amd64.deb -
Ubuntu rsync_2.6.9-3ubuntu1.2_i386.deb
i386 architecture (x86 compatible Intel/AMD) - Ubuntu 7.04
http://security.ubuntu.com/ubuntu/pool/main/r/rsync/rsync_2.6.9-3ubunt u1.2_i386.deb -
Ubuntu rsync_2.6.9-3ubuntu1.2_powerpc.deb
powerpc architecture (Apple Macintosh G3/G4/G5) - Ubuntu 7.04
http://security.ubuntu.com/ubuntu/pool/main/r/rsync/rsync_2.6.9-3ubunt u1.2_powerpc.deb -
Ubuntu rsync_2.6.9-3ubuntu1.2_sparc.deb
sparc architecture (Sun SPARC/UltraSPARC) - Ubuntu 7.04
http://security.ubuntu.com/ubuntu/pool/main/r/rsync/rsync_2.6.9-3ubunt u1.2_sparc.deb -
Ubuntu rsync_2.6.9-5ubuntu1.1_amd64.deb
amd64 architecture (Athlon64, Opteron, EM64T Xeon) - Ubuntu 7.10
http://security.ubuntu.com/ubuntu/pool/main/r/rsync/rsync_2.6.9-5ubunt u1.1_amd64.deb -
Ubuntu rsync_2.6.9-5ubuntu1.1_i386.deb
i386 architecture (x86 compatible Intel/AMD) - Ubuntu 7.10
http://security.ubuntu.com/ubuntu/pool/main/r/rsync/rsync_2.6.9-5ubunt u1.1_i386.deb -
Ubuntu rsync_2.6.9-5ubuntu1.1_powerpc.deb
powerpc architecture (Apple Macintosh G3/G4/G5) - Ubuntu 7.10
http://security.ubuntu.com/ubuntu/pool/main/r/rsync/rsync_2.6.9-5ubunt u1.1_powerpc.deb -
Ubuntu rsync_2.6.9-5ubuntu1.1_sparc.deb
sparc architecture (Sun SPARC/UltraSPARC) - Ubuntu 7.10
http://security.ubuntu.com/ubuntu/pool/main/r/rsync/rsync_2.6.9-5ubunt u1.1_sparc.deb
rsync rsync 3.0
-
rsync rsync-3.0.1-xattr-alloc.diff
http://rsync.samba.org/ftp/rsync/security/rsync-3.0.1-xattr-alloc.diff
rsync rsync 3.0.1
-
rsync rsync-3.0.1-xattr-alloc.diff
http://rsync.samba.org/ftp/rsync/security/rsync-3.0.1-xattr-alloc.diff
References
Rsync 'xattr' Support Integer Overflow Vulnerability
References:
References:
- cwRsync 2.1.3 is released (cwRsync)
- HP Insight Control suite for Linux Homepage (HP)
- rsync Homepage (rsync)
- Xattr security fix in 3.0.2 (rsync)