Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2025-0325

Опубликовано: 15 янв. 2025
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2025-0325: rsync security update (IMPORTANT)

[3.1.3-20]

  • Resolves: RHEL-70157 - Info Leak via Uninitialized Stack Contents

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

rsync

3.1.3-20.el8_10

rsync-daemon

3.1.3-20.el8_10

Oracle Linux x86_64

rsync

3.1.3-20.el8_10

rsync-daemon

3.1.3-20.el8_10

Связанные CVE

Связанные уязвимости

CVSS3: 7.5
ubuntu
5 месяцев назад

A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.

CVSS3: 7.5
redhat
5 месяцев назад

A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.

CVSS3: 7.5
nvd
5 месяцев назад

A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.

CVSS3: 7.5
msrc
5 месяцев назад

Описание отсутствует

CVSS3: 7.5
debian
5 месяцев назад

A flaw was found in rsync which could be triggered when rsync compares ...