Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Mageia: 2020-0108 Moderate: Rsync Security Update for Denial Of Service

mageia
Calendar Grey February 29, 2020
Dist Mageia Esm H88
Recent rsync updates tackle various vulnerabilities preventing potential crashes or unauthorized code execution. Keep your systems safe!
Updated rsync packages fix security vulnerabilities: It was discovered that rsync incorrectly handled pointer arithmetic in zlib

Summary

Updated rsync packages fix security vulnerabilities:
It was discovered that rsync incorrectly handled pointer arithmetic in zlib. An attacker could use this issue to cause rsync to crash, resulting in a denial of service, or possibly execute arbitrary code (CVE-2016-9840, CVE-2016-9841)
It was discovered that rsync incorrectly handled vectors involving left shifts of negative integers in zlib. An attacker could use this issue to cause rsync to crash, resulting in a denial of service, or possibly execute arbitrary code (CVE-2016-9842).
It was discovered that rsync incorrectly handled vectors involving big- endian CRC calculation in zlib. An attacker could use this issue to cause rsync to crash, resulting in a denial of service, or possibly execute arbitrary code (CVE-2016-9843).
Please note, we now compile against system zlib. If rsync fails to sync with older remote systems using compression (-z), you have either update the remote host to a newer version or disable compression.

References

- https://bugs.mageia.org/show_bug.cgi?id=26254

- https://www.cve.org/CVERecord?id=CVE-2016-9840

- https://www.cve.org/CVERecord?id=CVE-2016-9841

- https://www.cve.org/CVERecord?id=CVE-2016-9842

- https://www.cve.org/CVERecord?id=CVE-2016-9843

Resolution

SRPMS

- 7/core/rsync-3.1.3-4.mga7

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 29 Feb 2020
URL: https://advisories.mageia.org/MGASA-2020-0108.html
Type: security
CVE: CVE-2016-9840, CVE-2016-9841, CVE-2016-9842, CVE-2016-9843

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here