Bugzilla – Bug 1065646
VUL-0: CVE-2017-15994: rsync: rync mishandling archaic checksums could lead to access restrictions bypass
Last modified: 2017-11-28 15:35:27 UTC
CVE-2017-15994 rsync 3.1.3-development before 2017-10-24, as used in the xlucas svfs rsync fork and other products, mishandles archaic checksums, which makes it easier for remote attackers to bypass intended access restrictions. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-15994 http://www.cvedetails.com/cve/CVE-2017-15994/ http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15994 https://git.samba.org/?p=rsync.git;a=commit;h=c252546ceeb0925eb8a4061315e3ff0a8c55b48b https://git.samba.org/?p=rsync.git;a=commit;h=9a480deec4d20277d8e20bc55515ef0640ca1e55 https://git.samba.org/?p=rsync.git;a=commit;h=7b8a4ecd6ff9cdf4e5d3850ebf822f1e989255b3
None of the codestreams are affected by this bug as it was introduced in [0] after version 3.1.2 was released. See also [1]. openSUSE:Factory 3.1.2 SUSE:SLE-12:Update 3.1.0 SUSE:SLE-11-SP3:Update 3.0.4 SUSE:SLE-11-SP1:Update 3.0.4 SUSE:SLE-10-SP3:Update 2.6.8 [0] https://git.samba.org/?p=rsync.git;a=commit;h=a5a7d3a297b836387b0ac677383bdddaf2ac3598 [1] https://security-tracker.debian.org/tracker/CVE-2017-15994
Hi Thank you Pedro for your help and support!