|
|
| |
|
| |
rsync: arbitrary code execution
| Package(s): | rsync |
CVE #(s): | CVE-2011-1097
|
| Created: | March 29, 2011 |
Updated: | May 17, 2011 |
| Description: |
From the Red Hat advisory:
A memory corruption flaw was found in the way the rsync client processed
malformed file list data. If an rsync client used the "--recursive" and
"--delete" options without the "--owner" option when connecting to a
malicious rsync server, the malicious server could cause rsync on the
client system to crash or, possibly, execute arbitrary code with the
privileges of the user running rsync. |
| Alerts: |
|
( Log in to post comments)
|
|
|