Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 35036 - rsync 2.5.7 fixes vulnerability
Summary: rsync 2.5.7 fixes vulnerability
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All All
: High critical (vote)
Assignee: Gentoo Security
URL: http://rsync.samba.org/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2003-12-04 01:55 UTC by fbusse
Modified: 2011-10-30 22:38 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description fbusse 2003-12-04 01:55:26 UTC
rsync 2.5.7 fixes a remotly exploitable heap overflow, that, together with the do_brk bug in the kernel, could result in a remote root exploit.
I suggest an updated ebuild and a message to rsync-mirror admins ASAP.
Comment 1 Donnie Berkholz (RETIRED) gentoo-dev 2003-12-04 01:56:54 UTC
Already been done.
Comment 2 Seemant Kulleen (RETIRED) gentoo-dev 2003-12-04 01:58:01 UTC
we caught this as it came out from the rsync folks :)
Thanks for being vigilant as well though :)
Comment 3 Seemant Kulleen (RETIRED) gentoo-dev 2003-12-04 02:06:14 UTC
actually I'll reopen -- we may as well track the GLSA request with this bug
Comment 4 fbusse 2003-12-04 02:11:06 UTC
Is anybody going to check if the mirrors actually all updated rsyncd (and their kernel)?
Comment 5 solar (RETIRED) gentoo-dev 2003-12-04 07:27:56 UTC
Gentoo uses 105 mirrors world wide. Many of these mirror's are not even
using Gentoo or Linux so getting them to update thier kernels is going
to be quite a task, however a mail has been sent to the gentoo-mirrors@
mailing list regarding
http://marc.theaimsgroup.com/?l=rsync-announce&m=107051741303720&w=2

A complete list of rsync mirror's is being compiled now and remote 
version testing script is in the works.  What we are looking at doing
here is removing all servers from the main rotation and having them
report in when they have updated to version 2.5.7 if they are not 
already running 2.5.7

Everyone else should rsync with a mirror you trust then
emerge =net-misc/rsync-2.5.7
Comment 6 Seemant Kulleen (RETIRED) gentoo-dev 2003-12-07 09:49:59 UTC
closing since we've publicised this via glsa and gwn