CVE-2008-1720
published 2008-04-10CVE-2008-1720: Buffer overflow in rsync 2.6.9 to 3.0.1, with extended attribute (xattr) support enabled, might allow remote attackers to execute arbitrary code via unknown…
PriorityP339high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
4.98%
91.3th percentile
Buffer overflow in rsync 2.6.9 to 3.0.1, with extended attribute (xattr) support enabled, might allow remote attackers to execute arbitrary code via unknown vectors.
Affected
38 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | rsync | < rsync 3.0.2-1 (bookworm) | rsync 3.0.2-1 (bookworm) |
| samba | rsync | — | — |
| samba | rsync | — | — |
| samba | rsync | — | — |
| samba | rsync | — | — |
| samba | rsync | — | — |
| samba | rsync | — | — |
| samba | rsync | — | — |
| samba | rsync | — | — |
| samba | rsync | — | — |
| samba | rsync | — | — |
| samba | rsync | — | — |
| samba | rsync | — | — |
| samba | rsync | — | — |
| samba | rsync | — | — |
| samba | rsync | — | — |
| samba | rsync | — | — |
| samba | rsync | — | — |
| samba | rsync | — | — |
| samba | rsync | — | — |
| samba | rsync | — | — |
| samba | rsync | — | — |
| samba | rsync | — | — |
| samba | rsync | — | — |
| samba | rsync | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
rsync vulnerability
vendor_ubuntu·2008-04-11
CVE-2008-1720 rsync vulnerability
Title: rsync vulnerability
Summary: rsync vulnerability
Sebastian Krahmer discovered that rsync could overflow when handling ACLs.
An attacker could construct a malicious set of files that when processed
by rsync could lead to arbitrary code execution or a crash.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
rsync: integer overflow in xattr handling
vendor_redhat·2008-04-08·CVSS 7.5
CVE-2008-1720 [HIGH] CWE-190 rsync: integer overflow in xattr handling
rsync: integer overflow in xattr handling
Buffer overflow in rsync 2.6.9 to 3.0.1, with extended attribute (xattr) support enabled, might allow remote attackers to execute arbitrary code via unknown vectors.
Statement: Not vulnerable. This issue did not affect versions of rsync as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5.
Debian
CVE-2008-1720: rsync - Buffer overflow in rsync 2.6.9 to 3.0.1, with extended attribute (xattr) support...
vendor_debian·2008·CVSS 7.5
CVE-2008-1720 [HIGH] CVE-2008-1720: rsync - Buffer overflow in rsync 2.6.9 to 3.0.1, with extended attribute (xattr) support...
Buffer overflow in rsync 2.6.9 to 3.0.1, with extended attribute (xattr) support enabled, might allow remote attackers to execute arbitrary code via unknown vectors.
Scope: local
bookworm: resolved (fixed in 3.0.2-1)
bullseye: resolved (fixed in 3.0.2-1)
forky: resolved (fixed in 3.0.2-1)
sid: resolved (fixed in 3.0.2-1)
trixie: resolved (fixed in 3.0.2-1)
GHSA
GHSA-m92h-xg74-c2hm: Buffer overflow in rsync 2
ghsa_unreviewed·2022-05-01
CVE-2008-1720 [HIGH] CWE-119 GHSA-m92h-xg74-c2hm: Buffer overflow in rsync 2
Buffer overflow in rsync 2.6.9 to 3.0.1, with extended attribute (xattr) support enabled, might allow remote attackers to execute arbitrary code via unknown vectors.
OSV
CVE-2008-1720: Buffer overflow in rsync 2
osv·2008-04-10·CVSS 7.5
CVE-2008-1720 [HIGH] CVE-2008-1720: Buffer overflow in rsync 2
Buffer overflow in rsync 2.6.9 to 3.0.1, with extended attribute (xattr) support enabled, might allow remote attackers to execute arbitrary code via unknown vectors.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2008-4359 lighttpd: bypass of rewrite/redirect rules using encoded urls
bugzilla·2008-10-06·CVSS 7.5
CVE-2008-4359 [HIGH] CVE-2008-4359 lighttpd: bypass of rewrite/redirect rules using encoded urls
CVE-2008-4359 lighttpd: bypass of rewrite/redirect rules using encoded urls
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-4359 to the following vulnerability:
lighttpd before 1.4.20 compares URIs to patterns in the (1) url.redirect and
(2) url.rewrite configuration settings before performing URL decoding, which
might allow remote attackers to bypass intended access restrictions, and obtain
sensitive information or possibly modify data.
Affected versions:
all versions before 1.4.20 (1.5 before r2310)
Upstream advisory:
http://www.lighttpd.net/security/lighttpd_sa_2008_05.txt
Upstream bug report:
http://trac.lighttpd.net/trac/ticket/1720
Upstream patches (1.4.x):
http://www.lighttpd.net/security/lighttpd-1.4.x_rewrite_redirect_decode_url.patch
http://trac.lighttp
Bugzilla
CVE-2008-1720 rsync: integer overflow in xattr handling
bugzilla·2008-04-09·CVSS 7.5
CVE-2008-1720 [HIGH] CVE-2008-1720 rsync: integer overflow in xattr handling
CVE-2008-1720 rsync: integer overflow in xattr handling
Sebastian Krahmer of SuSE reported and integer overflow leading to a heap buffer
overflow in the xattr handling code (function expand_item_list()) used by rsync.
This issue affects rsync 2.6.9 and all rsync 3.x versions with xattr support
enabled. Upstream released version 3.0.2:
http://samba.anu.edu.au/rsync/security.html#s3_0_2
including the fix:
http://rsync.samba.org/ftp/rsync/security/rsync-3.0.1-xattr-alloc.diff
Upstream advisory also documents following mitigation to prevent exploitation of
the issue on affected versions:
Those running a writable rsync daemon can opt to refuse the "xattrs" option
as a way to avoid the problem without an upgrade:
refuse options = xattrs
(If you already refuse options, be sure to append
http://lists.opensuse.org/opensuse-security-announce/2008-05/msg00000.htmlhttp://marc.info/?l=bugtraq&m=125017764422557&w=2http://rsync.samba.org/ftp/rsync/security/rsync-3.0.1-xattr-alloc.diffhttp://samba.anu.edu.au/rsync/security.html#s3_0_2http://secunia.com/advisories/29668http://secunia.com/advisories/29770http://secunia.com/advisories/29777http://secunia.com/advisories/29781http://secunia.com/advisories/29788http://secunia.com/advisories/29856http://secunia.com/advisories/29861http://security.gentoo.org/glsa/glsa-200804-16.xmlhttp://sourceforge.net/project/shownotes.php?release_id=591462&group_id=69227http://www.debian.org/security/2008/dsa-1545http://www.mail-archive.com/rsync-announce%40lists.samba.org/msg00057.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:084http://www.osvdb.org/44368http://www.osvdb.org/44369http://www.securityfocus.com/bid/28726http://www.securitytracker.com/id?1019835http://www.vupen.com/english/advisories/2008/1191/referenceshttp://www.vupen.com/english/advisories/2008/1215/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/41766https://usn.ubuntu.com/600-1/https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00237.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-April/msg00247.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-05/msg00000.htmlhttp://marc.info/?l=bugtraq&m=125017764422557&w=2http://rsync.samba.org/ftp/rsync/security/rsync-3.0.1-xattr-alloc.diffhttp://samba.anu.edu.au/rsync/security.html#s3_0_2http://secunia.com/advisories/29668http://secunia.com/advisories/29770http://secunia.com/advisories/29777http://secunia.com/advisories/29781http://secunia.com/advisories/29788http://secunia.com/advisories/29856http://secunia.com/advisories/29861http://security.gentoo.org/glsa/glsa-200804-16.xmlhttp://sourceforge.net/project/shownotes.php?release_id=591462&group_id=69227http://www.debian.org/security/2008/dsa-1545http://www.mail-archive.com/rsync-announce%40lists.samba.org/msg00057.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:084http://www.osvdb.org/44368http://www.osvdb.org/44369http://www.securityfocus.com/bid/28726http://www.securitytracker.com/id?1019835http://www.vupen.com/english/advisories/2008/1191/referenceshttp://www.vupen.com/english/advisories/2008/1215/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/41766https://usn.ubuntu.com/600-1/https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00237.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-April/msg00247.html
2008-04-10
Published