rsync Client Incremental File List Remote Memory Corruption Vulnerability
BID:47064
Info
rsync Client Incremental File List Remote Memory Corruption Vulnerability
| Bugtraq ID: | 47064 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2011-1097 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 28 2011 12:00AM |
| Updated: | Apr 16 2015 06:07PM |
| Credit: | Wayne Davison and Matt McCutchen. |
| Vulnerable: |
Ubuntu Ubuntu Linux 9.10 sparc Ubuntu Ubuntu Linux 9.10 powerpc Ubuntu Ubuntu Linux 9.10 lpia Ubuntu Ubuntu Linux 9.10 i386 Ubuntu Ubuntu Linux 9.10 ARM Ubuntu Ubuntu Linux 9.10 amd64 Ubuntu Ubuntu Linux 10.10 powerpc Ubuntu Ubuntu Linux 10.10 i386 Ubuntu Ubuntu Linux 10.10 ARM Ubuntu Ubuntu Linux 10.10 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 SuSE SUSE Linux Enterprise 11 SP1 SuSE openSUSE 11.4 SuSE openSUSE 11.3 S.u.S.E. openSUSE 11.2 rsync rsync 3.0.2 rsync rsync 3.0.1 rsync rsync 3.0 rsync rsync 2.6.9 rsync rsync 2.6.8 rsync rsync 2.6.7 rsync rsync 2.6.6 rsync rsync 2.6.5 rsync rsync 2.6.2 rsync rsync 2.6.1 rsync rsync 2.6 rsync rsync 2.5.7 rsync rsync 2.5.6 rsync rsync 2.5.5 rsync rsync 2.5.4 rsync rsync 2.5.3 rsync rsync 2.5.2 rsync rsync 2.5.1 rsync rsync 2.5 .0 rsync rsync 2.4.8 rsync rsync 2.4.6 rsync rsync 2.4.5 rsync rsync 2.4.4 rsync rsync 2.4.3 rsync rsync 2.4.1 rsync rsync 2.4 .0 rsync rsync 2.3.2 -1.3 rsync rsync 2.3.2 -1.2 sparc rsync rsync 2.3.2 -1.2 PPC rsync rsync 2.3.2 -1.2 m68k rsync rsync 2.3.2 -1.2 intel rsync rsync 2.3.2 -1.2 ARM rsync rsync 2.3.2 -1.2 alpha rsync rsync 2.3.2 rsync rsync 2.3.1 rsync rsync 3.0.0pre6 Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux HPC Node 6 Red Hat Enterprise Linux Desktop 6 Mandriva Linux Mandrake 2010.1 x86_64 Mandriva Linux Mandrake 2010.1 Mandriva Linux Mandrake 2010.0 x86_64 Mandriva Linux Mandrake 2010.0 Mandriva Linux Mandrake 2009.0 x86_64 Mandriva Linux Mandrake 2009.0 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 HP Insight Control for Linux (IC-Linux) 7.0 Gentoo Linux |
| Not Vulnerable: | |
Discussion
rsync Client Incremental File List Remote Memory Corruption Vulnerability
The 'rsync' client is prone to a remote memory-corruption vulnerability.
An attacker can exploit this issue to execute arbitrary code with the privileges of the user running the affected application. Failed exploit attempts will result in a denial-of-service condition.
The 'rsync' client is prone to a remote memory-corruption vulnerability.
An attacker can exploit this issue to execute arbitrary code with the privileges of the user running the affected application. Failed exploit attempts will result in a denial-of-service condition.
Exploit / POC
rsync Client Incremental File List Remote Memory Corruption Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
rsync Client Incremental File List Remote Memory Corruption Vulnerability
References:
References:
- Bug 675036 - (CVE-2011-1097) CVE-2011-1097 rsync: Incremental file-list corrupti (Red Hat Bugzilla)
- rsync Homepage (rsync)