Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-12085

Опубликовано: 14 янв. 2025
Источник: debian
EPSS Средний

Описание

A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
rsyncfixed3.3.0+ds1-3package

Примечания

  • https://www.openwall.com/lists/oss-security/2025/01/14/3

  • Fixed by: https://git.samba.org/?p=rsync.git;a=commit;h=589b0691e59f761ccb05ddb8e1124991440db2c7 (v3.4.0)

  • https://phrack.org/issues/72/11_md#article

EPSS

Процентиль: 93%
0.11376
Средний

Связанные уязвимости

CVSS3: 7.5
ubuntu
10 месяцев назад

A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.

CVSS3: 7.5
redhat
10 месяцев назад

A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.

CVSS3: 7.5
nvd
10 месяцев назад

A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.

CVSS3: 7.5
msrc
10 месяцев назад

Rsync: info leak via uninitialized stack contents

rocky
10 месяцев назад

Important: rsync security update

EPSS

Процентиль: 93%
0.11376
Средний