LWN.net Logo

rsync: arbitrary code execution

Package(s):rsync CVE #(s):CVE-2011-1097
Created:March 29, 2011 Updated:May 17, 2011
Description: From the Red Hat advisory:

A memory corruption flaw was found in the way the rsync client processed malformed file list data. If an rsync client used the "--recursive" and "--delete" options without the "--owner" option when connecting to a malicious rsync server, the malicious server could cause rsync on the client system to crash or, possibly, execute arbitrary code with the privileges of the user running rsync.

Alerts:
Fedora FEDORA-2011-4427 2011-03-30
Fedora FEDORA-2011-4413 2011-03-30
Mandriva MDVSA-2011:066 2011-04-05
Red Hat RHSA-2011:0390-01 2011-03-28
SUSE SUSE-SR:2011:009 2011-05-17
Ubuntu USN-1124-1 2011-04-27
openSUSE openSUSE-SU-2011:0441-1 2011-05-06

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds