CVE-2011-1097
published 2011-03-30CVE-2011-1097: rsync 3.x before 3.0.8, when certain recursion, deletion, and ownership options are used, allows remote rsync servers to cause a denial of service (heap memory…
PriorityP427medium5.1CVSS 2.0
AVNACHAuNCPIPAP
EPSS
3.19%
86.8th percentile
rsync 3.x before 3.0.8, when certain recursion, deletion, and ownership options are used, allows remote rsync servers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via malformed data.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | rsync | < rsync 3.0.8 (bookworm) | rsync 3.0.8 (bookworm) |
| samba | rsync | — | — |
| samba | rsync | — | — |
| samba | rsync | — | — |
| samba | rsync | — | — |
| samba | rsync | — | — |
| samba | rsync | — | — |
| samba | rsync | — | — |
| samba | rsync | — | — |
| samba | rsync | >= 0 < 3.0.8 | 3.0.8 |
| samba | rsync | >= 0 < 3.0.8 | 3.0.8 |
| samba | rsync | >= 0 < 3.0.8 | 3.0.8 |
| samba | rsync | >= 0 < 3.0.8 | 3.0.8 |
CVSS provenance
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
osv5.1MEDIUM
vendor_debian5.1LOW
vendor_redhat5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
rsync vulnerability
vendor_ubuntu·2011-04-27
CVE-2011-1097 rsync vulnerability
Title: rsync vulnerability
Summary: rsync could be made to crash or run programs as your login if it connected
to a malicious server.
It was discovered that rsync incorrectly handled memory when certain
recursion, deletion and ownership options were used. If a user were tricked
into connecting to a malicious server, a remote attacker could cause a
denial of service or execute arbitrary code with privileges of the user
invoking the program.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
rsync: Incremental file-list corruption due to temporary file_extra_cnt increments
vendor_redhat·2011-03-26·CVSS 5.1
CVE-2011-1097 [MEDIUM] rsync: Incremental file-list corruption due to temporary file_extra_cnt increments
rsync: Incremental file-list corruption due to temporary file_extra_cnt increments
rsync 3.x before 3.0.8, when certain recursion, deletion, and ownership options are used, allows remote rsync servers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via malformed data.
Package: rsync (Red Hat Enterprise Linux 5) - Affected
Debian
CVE-2011-1097: rsync - rsync 3.x before 3.0.8, when certain recursion, deletion, and ownership options ...
vendor_debian·2011·CVSS 5.1
CVE-2011-1097 [MEDIUM] CVE-2011-1097: rsync - rsync 3.x before 3.0.8, when certain recursion, deletion, and ownership options ...
rsync 3.x before 3.0.8, when certain recursion, deletion, and ownership options are used, allows remote rsync servers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via malformed data.
Scope: local
bookworm: resolved (fixed in 3.0.8)
bullseye: resolved (fixed in 3.0.8)
forky: resolved (fixed in 3.0.8)
sid: resolved (fixed in 3.0.8)
trixie: resolved (fixed in 3.0.8)
GHSA
GHSA-rp4c-gxm3-wmf6: rsync 3
ghsa_unreviewed·2022-05-17
CVE-2011-1097 [MEDIUM] CWE-119 GHSA-rp4c-gxm3-wmf6: rsync 3
rsync 3.x before 3.0.8, when certain recursion, deletion, and ownership options are used, allows remote rsync servers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via malformed data.
OSV
CVE-2011-1097: rsync 3
osv·2011-03-30·CVSS 5.1
CVE-2011-1097 [MEDIUM] CVE-2011-1097: rsync 3
rsync 3.x before 3.0.8, when certain recursion, deletion, and ownership options are used, allows remote rsync servers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via malformed data.
No detection rules found.
No public exploits indexed.
http://gitweb.samba.org/?p=rsync.git%3Ba=commit%3Bh=83b94efa6b60a3ff5eee4c5f7812c617a90a03f6http://lists.fedoraproject.org/pipermail/package-announce/2011-April/057641.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-April/057736.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-April/057737.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.htmlhttp://lists.samba.org/archive/rsync/2011-January/025988.htmlhttp://marc.info/?l=bugtraq&m=133226187115472&w=2http://rsync.samba.org/ftp/rsync/src/rsync-3.0.8-NEWShttp://secunia.com/advisories/44071http://secunia.com/advisories/44088http://securitytracker.com/id?1025256http://www.mandriva.com/security/advisories?name=MDVSA-2011:066http://www.redhat.com/support/errata/RHSA-2011-0390.htmlhttp://www.vupen.com/english/advisories/2011/0792http://www.vupen.com/english/advisories/2011/0793http://www.vupen.com/english/advisories/2011/0873http://www.vupen.com/english/advisories/2011/0876https://bugzilla.redhat.com/show_bug.cgi?id=675036https://bugzilla.samba.org/show_bug.cgi?id=7936http://gitweb.samba.org/?p=rsync.git%3Ba=commit%3Bh=83b94efa6b60a3ff5eee4c5f7812c617a90a03f6http://lists.fedoraproject.org/pipermail/package-announce/2011-April/057641.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-April/057736.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-April/057737.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.htmlhttp://lists.samba.org/archive/rsync/2011-January/025988.htmlhttp://marc.info/?l=bugtraq&m=133226187115472&w=2http://rsync.samba.org/ftp/rsync/src/rsync-3.0.8-NEWShttp://secunia.com/advisories/44071http://secunia.com/advisories/44088http://securitytracker.com/id?1025256http://www.mandriva.com/security/advisories?name=MDVSA-2011:066http://www.redhat.com/support/errata/RHSA-2011-0390.htmlhttp://www.vupen.com/english/advisories/2011/0792http://www.vupen.com/english/advisories/2011/0793http://www.vupen.com/english/advisories/2011/0873http://www.vupen.com/english/advisories/2011/0876https://bugzilla.redhat.com/show_bug.cgi?id=675036https://bugzilla.samba.org/show_bug.cgi?id=7936
2011-03-30
Published