Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2025-0714

Опубликовано: 14 фев. 2025
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2025-0714: rsync security update (IMPORTANT)

[3.1.2-12.0.1]

  • Back port fix for CVE-2024-12085 [Orabug: 37524229]

Обновленные пакеты

Oracle Linux 7

Oracle Linux x86_64

rsync

3.1.2-12.0.1.el7_9

Связанные CVE

Связанные уязвимости

CVSS3: 7.5
ubuntu
5 месяцев назад

A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.

CVSS3: 7.5
redhat
5 месяцев назад

A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.

CVSS3: 7.5
nvd
5 месяцев назад

A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.

CVSS3: 7.5
msrc
5 месяцев назад

Описание отсутствует

CVSS3: 7.5
debian
5 месяцев назад

A flaw was found in rsync which could be triggered when rsync compares ...