Alerts This Week
Warning Icon 1 684
Alerts This Week
Warning Icon 1 684

Ubuntu 16.04 ESM USN-5359-2 Critical: rsync Denial Of Service

Ubuntu Large Esm H500
rsync could be made to crash or run programs if it received specially crafted network traffic.
=========================================================================Ubuntu Security Notice USN-5359-2
June 13, 2022

rsync vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 ESM

Summary:

rsync could be made to crash or run programs if it received
specially crafted network traffic.

Software Description:
- rsync: fast, versatile, remote (and local) file-copying tool

Details:

USN-5359-1 fixed vulnerabilities in rsync.
This update provides the corresponding updates for Ubuntu 16.04 ESM.

Original advisory details:

  Danilo Ramos discovered that rsync incorrectly handled memory when
  performing certain zlib deflating operations. An attacker could use this
  issue to cause rsync to crash, resulting in a denial of service, or
  possibly execute arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 ESM:
   rsync                           3.1.1-3ubuntu1.3+esm1

In general, a standard system update will make all the necessary changes.

References:
   https://ubuntu.com/security/notices/USN-5359-2
   https://ubuntu.com/security/notices/USN-5359-1
   CVE-2018-25032

Ubuntu 16.04 ESM USN-5359-2 Critical: rsync Denial Of Service

ubuntu
Calendar Grey June 13, 2022
Dist Ubuntu Esm H88
An issue in rsync on Ubuntu 16.04 ESM could lead to system failures and possible unauthorized code execution if network data is improperly handled.
rsync could be made to crash or run programs if it received specially crafted network traffic.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 ESM: rsync 3.1.1-3ubuntu1.3+esm1 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-5359-2

https://ubuntu.com/security/notices/USN-5359-1

CVE-2018-25032

Severity
critical
Lowest
Low
Medium
High
Critical

June 13, 2022

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here