Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 792576 (CVE-2020-14387) - <net-misc/rsync-3.2.3-r5: improper TLS validation in rsync-ssl script (CVE-2020-14387)
Summary: <net-misc/rsync-3.2.3-r5: improper TLS validation in rsync-ssl script (CVE-20...
Status: IN_PROGRESS
Alias: CVE-2020-14387
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: A3 [glsa]
Keywords: PullRequest
Depends on: 827218
Blocks:
  Show dependency tree
 
Reported: 2021-05-28 03:00 UTC by Sam James
Modified: 2024-03-24 10:38 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-05-28 03:00:43 UTC
Description:
"A flaw was found in rsync in versions since 3.2.0pre1. Rsync improperly validates certificate with host mismatch vulnerability. A remote, unauthenticated attacker could exploit the flaw by performing a man-in-the-middle attack using a valid certificate for another hostname which could compromise confidentiality and integrity of data transmitted using rsync-ssl. The highest threat from this vulnerability is to data confidentiality and integrity. This flaw affects rsync versions before 3.2.4."
Comment 1 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-05-28 03:03:44 UTC
Patch: https://git.samba.org/?p=rsync.git;a=commit;h=c3f7414
Comment 2 NATTkA bot gentoo-dev 2021-07-29 17:22:04 UTC Comment hidden (obsolete)
Comment 3 NATTkA bot gentoo-dev 2021-07-29 17:30:16 UTC Comment hidden (obsolete)
Comment 4 NATTkA bot gentoo-dev 2021-07-29 17:38:13 UTC Comment hidden (obsolete)
Comment 5 NATTkA bot gentoo-dev 2021-07-29 17:46:21 UTC Comment hidden (obsolete)
Comment 6 NATTkA bot gentoo-dev 2021-07-29 18:02:19 UTC Comment hidden (obsolete)
Comment 7 NATTkA bot gentoo-dev 2021-07-29 18:10:37 UTC
Package list is empty or all packages have requested keywords.
Comment 8 Larry the Git Cow gentoo-dev 2021-11-18 02:31:01 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=029532544d5edfe5fc70413a827831932e3c0b21

commit 029532544d5edfe5fc70413a827831932e3c0b21
Author:     Varsha Teratipally <teratipally@google.com>
AuthorDate: 2021-11-17 17:30:16 +0000
Commit:     Sam James <sam@gentoo.org>
CommitDate: 2021-11-18 02:30:46 +0000

    net-misc/rsync: fix CVE-2020-14387
    
    Bug: https://bugs.gentoo.org/792576
    Signed-off-by: Varsha Teratipally <teratipally@google.com>
    Closes: https://github.com/gentoo/gentoo/pull/22981
    Signed-off-by: Sam James <sam@gentoo.org>

 .../files/rsync-3.2.3-verify-certificate.patch     |  26 +++++
 net-misc/rsync/rsync-3.2.3-r5.ebuild               | 124 +++++++++++++++++++++
 2 files changed, 150 insertions(+)
Comment 9 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-11-26 05:08:32 UTC
Please cleanup
Comment 10 Hans de Graaff gentoo-dev Security 2023-10-05 12:20:15 UTC
commit 882b77edf896534ffd91d0fb17696bfda91e635b
Author: Sam James <sam@gentoo.org>
Date:   Sun Apr 17 18:00:47 2022 +0100

    net-misc/rsync: drop 3.2.3-r4