Heap-based buffer over-read in Rsync - CVE-2017-16548
Published: December 22, 2017
Vulnerability identifier: #VU9720
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-16548
CWE-ID: CWE-126
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists due to the receive_xattr function in xattrs.c does not check for a trailing '' character in an xattr name. A remote attacker can send specially crafted data to the daemon, trigger heap-based buffer over-read and cause the application to crash.
The weakness exists due to the receive_xattr function in xattrs.c does not check for a trailing '' character in an xattr name. A remote attacker can send specially crafted data to the daemon, trigger heap-based buffer over-read and cause the application to crash.
Affected software
Rsync
Debian Linux
Gentoo Linux
Arch Linux
Ubuntu
Slackware Linux
rsync (Alpine package)
Debian Linux
Gentoo Linux
Arch Linux
Ubuntu
Slackware Linux
rsync (Alpine package)
How to mitigate CVE-2017-16548
Install update from vendor's website.
rsync (Alpine package) - update to 3.1.2-r3