Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.50395
Category:Fedora Local Security Checks
Title:Fedora Core 2 FEDORA-2004-269 (rsync)
Summary:NOSUMMARY
Description:Description:

The remote host is missing an update to rsync
announced via advisory FEDORA-2004-269.

Rsync uses a reliable algorithm to bring remote and host files into
sync very quickly. Rsync is fast because it just sends the differences
in the files over the network instead of sending the complete
files. Rsync is often used as a very powerful mirroring process or
just as a more capable replacement for the rcp command. A technical
report which describes the rsync algorithm is included in this
package.

Update Information:

This update backports a security fix to a path-sanitizing flaw that
affects rsync when it is used in daemon mode without also using
chroot.

For more information see http://samba.org/rsync/#security_aug04

This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/

d6ae9d1c6e5d18903911e1fdedd55a03 SRPMS/rsync-2.6.2-1.fc2.0.src.rpm
f03bc05659c874cb39d4bab606dfaabf x86_64/rsync-2.6.2-1.fc2.0.x86_64.rpm
97f2ed68e7b3f7e0c5888b0aa8cd2088 x86_64/debug/rsync-debuginfo-2.6.2-1.fc2.0.x86_64.rpm
1dd097feb524de781f6ae9ecf74bcc3d i386/rsync-2.6.2-1.fc2.0.i386.rpm
38590683c5bca0a599fbc70a971c6b7e i386/debug/rsync-debuginfo-2.6.2-1.fc2.0.i386.rpm

This update can also be installed with the Update Agent
you can
launch the Update Agent with the 'up2date' command.


Solution: Apply the appropriate updates.
http://www.fedoranews.org/updates/FEDORA-2004-269.shtml

Risk factor : High

CVSS Score:
6.4

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2004-0792
Bugtraq: 20040816 TSSA-2004-020-ES - rsync (Google Search)
http://marc.info/?l=bugtraq&m=109268147522290&w=2
Bugtraq: 20040817 LNSA-#2004-0017: rsync (Aug, 17 2004) (Google Search)
http://marc.info/?l=bugtraq&m=109277141223839&w=2
Debian Security Information: DSA-538 (Google Search)
http://www.debian.org/security/2004/dsa-538
http://www.gentoo.org/security/en/glsa/glsa-200408-17.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2004:083
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10561
SuSE Security Announcement: SUSE-SA:2004:026 (Google Search)
http://www.novell.com/linux/security/advisories/2004_26_rsync.html
http://www.trustix.net/errata/2004/0042/
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.