Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-85h7-m8c3-v9wc

Опубликовано: 15 янв. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), an attacker can write out of bounds in the sum2 buffer.

A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), an attacker can write out of bounds in the sum2 buffer.

EPSS

Процентиль: 89%
0.04812
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-122
CWE-787

Связанные уязвимости

CVSS3: 9.8
ubuntu
10 месяцев назад

A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), an attacker can write out of bounds in the sum2 buffer.

CVSS3: 9.8
redhat
10 месяцев назад

A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), an attacker can write out of bounds in the sum2 buffer.

CVSS3: 9.8
nvd
10 месяцев назад

A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), an attacker can write out of bounds in the sum2 buffer.

CVSS3: 9.8
msrc
10 месяцев назад

Rsync: heap buffer overflow in rsync due to improper checksum length handling

CVSS3: 9.8
debian
10 месяцев назад

A heap-based buffer overflow flaw was found in the rsync daemon. This ...

EPSS

Процентиль: 89%
0.04812
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-122
CWE-787