Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.1.10.2017.0452
Kategorie:Mageia Linux Local Security Checks
Titel:Mageia: Security Advisory (MGASA-2017-0452)
Zusammenfassung:The remote host is missing an update for the 'rsync' package(s) announced via the MGASA-2017-0452 advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'rsync' package(s) announced via the MGASA-2017-0452 advisory.

Vulnerability Insight:
The recv_files function in receiver.c in the daemon in rsync 3.1.2, and
3.1.3-development before 2017-12-03, proceeds with certain file metadata
updates before checking for a filename in the daemon_filter_list data
structure, which allows remote attackers to bypass intended access
restrictions. (CVE-2017-17433)

The daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, does
not check for fnamecmp filenames in the daemon_filter_list data
structure (in the recv_files function in receiver.c) and also does not
apply the sanitize_paths protection mechanism to pathnames found in
'xname follows' strings (in the read_ndx_and_attrs function in rsync.c),
which allows remote attackers to bypass intended access restrictions.
(CVE-2017-17434)

Affected Software/OS:
'rsync' package(s) on Mageia 5, Mageia 6.

Solution:
Please install the updated package(s).

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2017-17433
Debian Security Information: DSA-4068 (Google Search)
https://www.debian.org/security/2017/dsa-4068
https://git.samba.org/?p=rsync.git;a=commit;h=3e06d40029cfdce9d0f73d87cfd4edaf54be9c51
https://lists.debian.org/debian-lts-announce/2017/12/msg00020.html
Common Vulnerability Exposure (CVE) ID: CVE-2017-17434
https://git.samba.org/?p=rsync.git;a=commit;h=5509597decdbd7b91994210f700329d8a35e70a1
https://git.samba.org/?p=rsync.git;a=commit;h=70aeb5fddd1b2f8e143276f8d5a085db16c593b9
CopyrightCopyright (C) 2022 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.