Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-16548

Опубликовано: 06 нояб. 2017
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 7.5
CVSS3: 9.8

Описание

The receive_xattr function in xattrs.c in rsync 3.1.2 and 3.1.3-development does not check for a trailing '\0' character in an xattr name, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact by sending crafted data to the daemon.

РелизСтатусПримечание
artful

released

3.1.2-2ubuntu0.2
devel

not-affected

3.1.2-2.1
esm-infra-legacy/trusty

released

3.1.0-2ubuntu0.4
esm-infra/xenial

released

3.1.1-3ubuntu1.2
precise/esm

not-affected

3.0.9-1ubuntu1.3
trusty

released

3.1.0-2ubuntu0.4
trusty/esm

released

3.1.0-2ubuntu0.4
upstream

needs-triage

xenial

released

3.1.1-3ubuntu1.2
zesty

ignored

end of life

Показывать по

EPSS

Процентиль: 86%
0.02941
Низкий

7.5 High

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 6.5
redhat
больше 8 лет назад

The receive_xattr function in xattrs.c in rsync 3.1.2 and 3.1.3-development does not check for a trailing '\0' character in an xattr name, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact by sending crafted data to the daemon.

CVSS3: 9.8
nvd
больше 8 лет назад

The receive_xattr function in xattrs.c in rsync 3.1.2 and 3.1.3-development does not check for a trailing '\0' character in an xattr name, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact by sending crafted data to the daemon.

CVSS3: 9.8
debian
больше 8 лет назад

The receive_xattr function in xattrs.c in rsync 3.1.2 and 3.1.3-develo ...

CVSS3: 9.8
github
больше 3 лет назад

The receive_xattr function in xattrs.c in rsync 3.1.2 and 3.1.3-development does not check for a trailing '\0' character in an xattr name, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact by sending crafted data to the daemon.

CVSS3: 9.8
fstec
больше 8 лет назад

Уязвимость функции receive_xattr в xattrs.c утилиты для передачи и синхронизации файлов Rsync, связанная с чтением за допустимыми границами буфера данных, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

EPSS

Процентиль: 86%
0.02941
Низкий

7.5 High

CVSS2

9.8 Critical

CVSS3