Bugzilla – Bug 48478
VUL-0: CVE-2003-0962: rsync: Remotely exploitable heap overflow
Last modified: 2017-04-21 09:18:53 UTC
Andrew Tridgell just announced a new version of rsync, which fixes a remotely exploitable heap overflow. This vulnerability was supposedly used to break into the Gentoo server. Version 2.5.7 is available from rsync.samba.org I've started to work on creating fixed packages
<!-- SBZ_reproduce --> -
Working in patches
CAN-2003-0962
packages approved adv. will be released in a few minutes
done
CVE-2003-0962: CVSS v2 Base Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)