SUSE-SU-2018:0118-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2018:0118-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2018:0118-1
Related
Published
2018-01-17T07:31:45Z
Modified
2018-01-17T07:31:45Z
Summary
Security update for rsync
Details

This update for rsync fixes several issues.

These security issues were fixed:

  • CVE-2017-17434: The daemon in rsync did not check for fnamecmp filenames in the daemonfilterlist data structure (in the recvfiles function in receiver.c) and also did not apply the sanitizepaths protection mechanism to pathnames found in 'xname follows' strings (in the readndxand_attrs function in rsync.c), which allowed remote attackers to bypass intended access restrictions' (bsc#1071460).
  • CVE-2017-17433: The recvfiles function in receiver.c in the daemon in rsync, proceeded with certain file metadata updates before checking for a filename in the daemonfilter_list data structure, which allowed remote attackers to bypass intended access restrictions (bsc#1071459).
  • CVE-2017-16548: The receive_xattr function in xattrs.c in rsync did not check for a trailing '\0' character in an xattr name, which allowed remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact by sending crafted data to the daemon (bsc#1066644).

This non-security issue was fixed:

  • Stop file upload after errors like a full disk (bsc#1062063)
  • Ensure -X flag works even when setting owner/group (bsc#1028842)
References

Affected packages

SUSE:Linux Enterprise Desktop 12 SP2 / rsync

Package

Name
rsync
Purl
purl:rpm/suse/rsync&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.1.0-13.7.1

Ecosystem specific

{
    "binaries": [
        {
            "rsync": "3.1.0-13.7.1"
        }
    ]
}

SUSE:Linux Enterprise Desktop 12 SP3 / rsync

Package

Name
rsync
Purl
purl:rpm/suse/rsync&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.1.0-13.7.1

Ecosystem specific

{
    "binaries": [
        {
            "rsync": "3.1.0-13.7.1"
        }
    ]
}

SUSE:Linux Enterprise Server for Raspberry Pi 12 SP2 / rsync

Package

Name
rsync
Purl
purl:rpm/suse/rsync&distro=SUSE%20Linux%20Enterprise%20Server%20for%20Raspberry%20Pi%2012%20SP2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.1.0-13.7.1

Ecosystem specific

{
    "binaries": [
        {
            "rsync": "3.1.0-13.7.1"
        }
    ]
}

SUSE:Linux Enterprise Server 12 SP2 / rsync

Package

Name
rsync
Purl
purl:rpm/suse/rsync&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.1.0-13.7.1

Ecosystem specific

{
    "binaries": [
        {
            "rsync": "3.1.0-13.7.1"
        }
    ]
}

SUSE:Linux Enterprise Server for SAP Applications 12 SP2 / rsync

Package

Name
rsync
Purl
purl:rpm/suse/rsync&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.1.0-13.7.1

Ecosystem specific

{
    "binaries": [
        {
            "rsync": "3.1.0-13.7.1"
        }
    ]
}

SUSE:Linux Enterprise Server 12 SP3 / rsync

Package

Name
rsync
Purl
purl:rpm/suse/rsync&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.1.0-13.7.1

Ecosystem specific

{
    "binaries": [
        {
            "rsync": "3.1.0-13.7.1"
        }
    ]
}

SUSE:Linux Enterprise Server for SAP Applications 12 SP3 / rsync

Package

Name
rsync
Purl
purl:rpm/suse/rsync&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.1.0-13.7.1

Ecosystem specific

{
    "binaries": [
        {
            "rsync": "3.1.0-13.7.1"
        }
    ]
}