oss-sec mailing list archives
Re: CVE Request: rsync denial of service
From: cve-assign () mitre org
Date: Tue, 15 Apr 2014 10:05:48 -0400 (EDT)
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1
rsync 3.1.0 contains a denial of service issue
a remote client can send an invalid username and cause an infinite CPU loop on the server child process. The server master process is unaffected, allowing the remote client to do this multiple times toward system-wide denial of service.
Wayne Davison 2014-04-13 21:14:04 UTC I've committed a fix for this into git for release in 3.1.1.
https://bugzilla.samba.org/show_bug.cgi?id=10551 https://bugs.launchpad.net/ubuntu/+source/rsync/+bug/1307230 https://git.samba.org/?p=rsync.git;a=commit;h=0dedfbce2c1b851684ba658861fe9d620636c56a Use CVE-2014-2855. - -- CVE assignment team, MITRE CVE Numbering Authority M/S M300 202 Burlington Road, Bedford, MA 01730 USA [ PGP key available through http://cve.mitre.org/cve/request_id.html ] -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.14 (SunOS) iQEcBAEBAgAGBQJTTTxZAAoJEKllVAevmvms0osIAISAV1FFI1QsgpIaAzizTP7I JvnQ60EWLWlgHSAmTEEByU9GIzNIpgkccUt5MuTU55kbs/Twybxk1jBJwLbRv+57 lugTYi8gmKV26W1dnYY6gIEo3QyJNAXMK9I+4/fW8MSsPdkP3R7LumHagwoEryI5 vH1YVqwfFz49s9tQ3G2QY9i6B2gKEgPjmFo2n/K+UJAgD9rtqA8QCAGKd1XfdPPL aG2Q2q31WfFw9w4fwDTEhY7s9Tn1Y+0f7HraJY9g6hqptSztxqH90wo9vzPthzs6 Io4MvYtwvQR725imLaSS51PiVYhqEBU22uV9fH8j/8NJvImmMNoFpelX4J1NBKY= =U7Ut -----END PGP SIGNATURE-----
Current thread:
- CVE Request: rsync denial of service Marc Deslauriers (Apr 14)
- Re: CVE Request: rsync denial of service cve-assign (Apr 15)
