Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2025-0324

Опубликовано: 15 янв. 2025
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2025-0324: rsync security update (IMPORTANT)

[3.2.3-20.1]

  • Resolves: RHEL-72495 - Info Leak via Uninitialized Stack Contents

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

rsync

3.2.3-20.el9_5.1

rsync-daemon

3.2.3-20.el9_5.1

Oracle Linux x86_64

rsync

3.2.3-20.el9_5.1

rsync-daemon

3.2.3-20.el9_5.1

Связанные CVE

Связанные уязвимости

CVSS3: 7.5
ubuntu
5 месяцев назад

A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.

CVSS3: 7.5
redhat
5 месяцев назад

A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.

CVSS3: 7.5
nvd
5 месяцев назад

A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.

CVSS3: 7.5
msrc
5 месяцев назад

Описание отсутствует

CVSS3: 7.5
debian
5 месяцев назад

A flaw was found in rsync which could be triggered when rsync compares ...