(Conectiva Issues Fix) Rsync Heap Overflow in Daemon Mode Lets Remote Users Execute Arbitrary Code
|
|
SecurityTracker Alert ID: 1008394 |
|
SecurityTracker URL: http://securitytracker.com/id/1008394
|
|
CVE Reference:
CAN-2003-0962
(Links to External Site)
|
Date: Dec 5 2003
|
Impact:
Execution of arbitrary code via network, User access via network
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): 2.5.6 and prior versions
|
Description:
A vulnerability was reported in rsync. A remote user can execute arbitrary code on the target system.
It is reported that a remote user can connect to a target server running rsync on TCP port 873 and send specially crafted data to execute arbitrary code. The code will run with the privileges of the rsync daemon.
Only systems that are running rsync in daemon mode are reportedly affected.
|
Impact:
A remote user can execute arbitrary code with the privileges of the rsync daemon.
|
Solution:
Conectiva has released a fix.
ftp://atualizacoes.conectiva.com.br/8/SRPMS/rsync-2.5.7-5U80_1cl.src.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/rsync-2.5.7-5U80_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/SRPMS/rsync-2.5.7-13508U90_1cl.src.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/rsync-2.5.7-13508U90_1cl.i386.rpm
|
Vendor URL: rsync.samba.org/ (Links to External Site)
|
Cause:
Boundary error
|
Underlying OS:
Linux (Conectiva)
|
|
Message History:
This archive entry is a follow-up to the message listed below.
|
Source Message Contents
|
Date: Thu, 4 Dec 2003 18:46:41 -0200
Subject: [conectiva-updates] [CLA-2003:794] Conectiva Security Announcement - rsync
|
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
- --------------------------------------------------------------------------
CONECTIVA LINUX SECURITY ANNOUNCEMENT
- --------------------------------------------------------------------------
PACKAGE : rsync
SUMMARY : Fix for remote vulnerability
DATE : 2003-12-04 18:46:00
ID : CLA-2003:794
RELEVANT
RELEASES : 8, 9
- -------------------------------------------------------------------------
DESCRIPTION
"rsync"[1] is a program used mainly to mirror files between remote
sites.
rsync versions prior to 2.5.7 have a heap buffer overflow
vulnerability[2] which can be exploited by remote attackers to
execute arbitrary code.
This vulnerability specially affects installations where rsync is
used as a server/daemon, that is, where it was started with the
--daemon command line argument.
A new rsync version, 2.5.7, was released by the authors to address
this vulnerability.
SOLUTION
It is recommended that all rsync users upgrade their packages.
IMPORTANT: after the update, the rsync server must be restarted
manually if it was already running.
REFERENCES
1. http://rsync.samba.org/
2. http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0962
UPDATED PACKAGES
ftp://atualizacoes.conectiva.com.br/8/SRPMS/rsync-2.5.7-5U80_1cl.src.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/rsync-2.5.7-5U80_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/SRPMS/rsync-2.5.7-13508U90_1cl.src.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/rsync-2.5.7-13508U90_1cl.i386.rpm
ADDITIONAL INSTRUCTIONS
The apt tool can be used to perform RPM packages upgrades:
- run: apt-get update
- after that, execute: apt-get upgrade
Detailed instructions reagarding the use of apt and upgrade examples
can be found at http://distro.conectiva.com.br/atualizacoes/#apt?idioma=en
- -------------------------------------------------------------------------
All packages are signed with Conectiva's GPG key. The key and instructions
on how to import it can be found at
http://distro.conectiva.com.br/seguranca/chave/?idioma=en
Instructions on how to check the signatures of the RPM packages can be
found at http://distro.conectiva.com.br/seguranca/politica/?idioma=en
- -------------------------------------------------------------------------
All our advisories and generic update instructions can be viewed at
http://distro.conectiva.com.br/atualizacoes/?idioma=en
- -------------------------------------------------------------------------
Copyright (c) 2003 Conectiva Inc.
http://www.conectiva.com
- -------------------------------------------------------------------------
subscribe: conectiva-updates-subscribe@papaleguas.conectiva.com.br
unsubscribe: conectiva-updates-unsubscribe@papaleguas.conectiva.com.br
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (GNU/Linux)
Comment: For info see http://www.gnupg.org
iD8DBQE/z50v42jd0JmAcZARAi28AKC87tMeZ78lZDrz7r2VQ37VLcE3FQCg0639
36tHDoREvYy7zxf45fVsP0U=
=rxDT
-----END PGP SIGNATURE-----
|
|