Security restrictions bypass in Rsync - CVE-2018-5764
Published: January 25, 2018 / Updated: January 29, 2018
Vulnerability identifier: #VU10307
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-5764
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass security controls on the target system.
The weakness exists in the parse_arguments() function in 'options.c' due to insufficient validation of user-supplied input. A remote attacker can send multiple '--protect-args' values and bypass the argument-sanitization protection mechanism.
The weakness exists in the parse_arguments() function in 'options.c' due to insufficient validation of user-supplied input. A remote attacker can send multiple '--protect-args' values and bypass the argument-sanitization protection mechanism.
Affected software
Rsync
Arch Linux
Gentoo Linux
Amazon Linux AMI
Ubuntu
Slackware Linux
Fedora
rsync (Alpine package)
httpd24
rsync
Cloud Pak for Network Automation
IBM Cloud Pak for Watson AIOps
Arch Linux
Gentoo Linux
Amazon Linux AMI
Ubuntu
Slackware Linux
Fedora
rsync (Alpine package)
httpd24
rsync
Cloud Pak for Network Automation
IBM Cloud Pak for Watson AIOps
How to mitigate CVE-2018-5764
Update to version 3.1.3.
rsync (Alpine package) - update to 3.1.3-r0
httpd24 - update to 2.4.61-1.103
Cloud Pak for Network Automation - update to 2.6.5
rsync - addressed in versions 3.1.3-1.fc26, 3.1.3-1.fc27, 3.1.3-2.fc26
IBM Cloud Pak for Watson AIOps - update to 4.2.0
httpd24 - update to 2.4.61-1.103
Cloud Pak for Network Automation - update to 2.6.5
rsync - addressed in versions 3.1.3-1.fc26, 3.1.3-1.fc27, 3.1.3-2.fc26
IBM Cloud Pak for Watson AIOps - update to 4.2.0
External References
Related Security Bulletins
- Security restrictions bypass in Samba Rsync
- Ubuntu update for rsync
- Ubuntu update for rsync
- Arch Linux update for rsync
- Slackware Linux update for rsync
- Gentoo update for rsync
- Security restrictions bypass in rsync (Alpine package)
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- Multiple vulnerabilities in IBM Cloud Pak for Network Automation
- Amazon Linux AMI update for httpd24
- Fedora 26 update for rsync
- Fedora 27 update for rsync
- Fedora 26 update for rsync