You are here
Home > Preporuke > Sigurnosni nedostatak programskog paketa rsync

Sigurnosni nedostatak programskog paketa rsync

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LUB

==========================================================================
Ubuntu Security Notice USN-2171-1
April 23, 2014

rsync vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 14.04 LTS

Summary:

rsync could be made to consume resources if it received specially crafted
network traffic.

Software Description:
– rsync: fast, versatile, remote (and local) file-copying tool

Details:

Ryan Finnie discovered that the rsync daemon incorrectly handled invalid
usernames. A remote attacker could use this issue to cause rsync to consume
resources, resulting in a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS:
rsync 3.1.0-2ubuntu0.1

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2171-1
CVE-2014-2855

Package Information:
https://launchpad.net/ubuntu/+source/rsync/3.1.0-2ubuntu0.1

—–BEGIN PGP SIGNATURE—–
Version: GnuPG v1
Comment: Using GnuPG with Thunderbird – http://www.enigmail.net/

iQIcBAEBCgAGBQJTV9LaAAoJEGVp2FWnRL6TSrMP/0SbVaUV6VuHpobhFcF5046l
X5HSgh5zMWNCUIeISaTfHEF4v89WZ0dSnosLU9ovqf9zmv6O96Vb3iBH3oMtEnDG
dVaVWmeix4Nam6WogCgeQzvFxDFdq0JNt5Q0PuOBCIgkn2tQXDiXDeNgPBj/B4bs
VdrgHL3q7qCa1s74vxwvQdyywl1CW7Yu/GwwxvReAMK3/ZlJOKDLnUMC4q+CuVtW
YwrgetLgS+ll29ngykGEEwf4kUKFJNV07UFx9qyGrQN8Ohn8hTVrts5gQ7X4hVMe
5yRNPoVHPAVcqExjAKWzFCfTnRjo0Y9a9sOY7Vxe9d/KSlWjgK9nQT1Hqtg58use
Ksx6WmuNhf2knYXhui2l4kvl0RDxBveA9usLL+6K5+5pUX98zCIXkI53wr8iIVc3
XR9a29w+LdliBo5WYWGvD972iMbbOBFVQt9boM8jroDiI5iKuqEc619DHshVevP6
XbraUvUX78ZuGfJhYv+X0NL/6i1Gv3+LrHseU1KLgm6Du5Mwa7aR0/VkYi6PtkQF
HhMU144RXgbeEb6valD/oXbqexfrVRva9NMSZx1QEAYxfVmZ+XfsTHYU6jknifmE
egRI1BFNxuQ6zSa3bjZwKO8ReAWGbWyXLHU39dVRLzKPSk+Xyn30tblWnwed2jZg
Y5Shiv98dH+45DM4w5uY
=t6D1
—–END PGP SIGNATURE—–

AutorMarijo Plepelic
Cert idNCERT-REF-2014-04-0013-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
Izvorhttp://www.adobe.com/
Top
More in Preporuke
Sigurnosni nedostatak programskog paketa syncevolution

Otkriveni je sigurnosni nedostatak u programskom paketu syncevolution za operacijski sustav Fedora. Otkriveni nedostatak potencijalnim napadačima omogućuje da izvođenjem napada...

Close