Dit bericht is nog niet vertaald

[USN-600-1] rsync vulnerability

Ubuntu Security Notice USN-600-1             April 11, 2008
rsync vulnerability
CVE-2008-1720
Kwetsbare Ubuntu versies:

Ubuntu 7.04
Ubuntu 7.10

Kwetsbare pakketten:

Ubuntu 7.04
rsync 2.6.9-3ubuntu1.2
Ubuntu 7.10
rsync 2.6.9-5ubuntu1.1

In general, a standard system upgrade is sufficient to effect the necessary changes.

Sebastian Krahmer discovered that rsync could overflow when handling ACLs. An attacker could construct a malicious set of files that when processed by rsync could lead to arbitrary code execution or a crash.