Summary: | net-misc/rsync <= 2.6.9-r2 two off-by-one stack overflows (CVE-2007-4091) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Tobias Scherbaum (RETIRED) <dertobi123> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | major | CC: | base-system, bernd, fauli, gentoo, grag, ks, rajiv, wschlich |
Priority: | High | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4091 | ||
Whiteboard: | A2 [glsa] | ||
Package list: | Runtime testing required: | --- |
Description
Tobias Scherbaum (RETIRED)
![]() Tested the patch applied to 2.6.9-r2, seems to be working fine on the rsync-Mirror I maintain. Thanks for the report Tobias. base-system, please bump as necessary. *** Bug 189694 has been marked as a duplicate of this bug. *** Patch added to -r3 Arches please test and mark stable. Target keywords are: rsync-2.6.9-r3.ebuild:KEYWORDS="alpha amd64 arm hppa ia64 m68k mips ppc ppc64 s390 sh sparc ~sparc-fbsd x86 ~x86-fbsd" already stable for ppc sparc stable. x86 done amd64 stable Stable for HPPA. alpha/ia64 stable ppc64 stable All security supported arches done, changing status to [glsa], security your part. glsa request filed, which makes the 20th draft waiting in the pool... *sigh* 200709-13 ... be patient :) |