[<prev] [next>] [<thread-prev] [month] [year] [list]
Date: Thu, 10 Apr 2008 14:28:33 -0400 (EDT)
From: "Steven M. Christey" <coley@...us.mitre.org>
To: Josh Bressers <bressers@...hat.com>
Subject: Re: CVE Request (rsync)
======================================================
Name: CVE-2008-1720
Status: Candidate
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1720
Reference: CONFIRM:http://rsync.samba.org/ftp/rsync/security/rsync-3.0.1-xattr-alloc.diff
Reference: CONFIRM:http://samba.anu.edu.au/rsync/security.html#s3_0_2
Buffer overflow in rsync 2.6.9 to 3.0.1, with extended attribute
(xattr) support enabled, might allow remote attackers to execute
arbitrary code via unknown vectors.
Please check out the
Open Source Software Security Wiki, which is counterpart to this
mailing list.
Hosted by DataForce ISP -
Powered by Openwall GNU/*/Linux