From: Peter Korsgaard <peter@korsgaard.com>
To: buildroot@buildroot.org
Cc: Bernd Kuhls <bernd@kuhls.net>
Subject: Re: [Buildroot] [PATCH] package/rsync: security bump to version 3.4.0
Date: Wed, 22 Jan 2025 16:05:37 +0100 [thread overview]
Message-ID: <87plkenb26.fsf@dell.be.48ers.dk> (raw)
In-Reply-To: <20250115163310.164964-1-peter@korsgaard.com> (Peter Korsgaard's message of "Wed, 15 Jan 2025 17:33:09 +0100")
>>>>> "Peter" == Peter Korsgaard <peter@korsgaard.com> writes:
> Fixes the following vulnerabilities:
> CVE-2024-12084: Heap Buffer Overflow in Rsync due to Improper Checksum
> Length Handling
> Description: A heap-based buffer overflow flaw was found in the rsync
> daemon. This issue is due to improper handling of attacker-controlled
> checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the
> fixed SUM_LENGTH (16 bytes), an attacker can write out of bounds in the
> sum2 buffer.
> CVE-2024-12085: Info Leak via Uninitialized Stack Contents
> Description: A flaw was found in the rsync daemon which could be triggered
> when rsync compares file checksums. This flaw allows an attacker to
> manipulate the checksum length (s2length) to cause a comparison between a
> checksum and uninitialized memory and leak one byte of uninitialized stack
> data at a time.
> CVE-2024-12086: Rsync Server Leaks Arbitrary Client Files
> Description: A flaw was found in rsync. It could allow a server to
> enumerate the contents of an arbitrary file from the client's machine. This
> issue occurs when files are being copied from a client to a server. During
> this process, the rsync server will send checksums of local data to the
> client to compare with in order to determine what data needs to be sent to
> the server. By sending specially constructed checksum values for arbitrary
> files, an attacker may be able to reconstruct the data of those files
> byte-by-byte based on the responses from the client.
> CVE-2024-12087: Path Traversal Vulnerability in Rsync
> Description: A path traversal vulnerability exists in rsync. It stems from
> behavior enabled by the `--inc-recursive` option, a default-enabled option
> for many client options and can be enabled by the server even if not
> explicitly enabled by the client. When using the `--inc-recursive` option,
> a lack of proper symlink verification coupled with deduplication checks
> occurring on a per-file-list basis could allow a server to write files
> outside of the client's intended destination directory. A malicious server
> could write malicious files to arbitrary locations named after valid
> directories/paths on the client.
> CVE-2024-12088: --safe-links Option Bypass Leads to Path Traversal
> Description: A flaw was found in rsync. When using the `--safe-links`
> option, rsync fails to properly verify if a symbolic link destination
> contains another symbolic link within it. This results in a path traversal
> vulnerability, which may lead to arbitrary file write outside the desired
> directory.
> CVE-2024-12747: Race Condition in Rsync Handling Symbolic Links
> Description: A flaw was found in rsync. This vulnerability arises from a
> race condition during rsync's handling of symbolic links. Rsync's default
> behavior when encountering symbolic links is to skip them. If an attacker
> replaced a regular file with a symbolic link at the right time, it was
> possible to bypass the default behavior and traverse symbolic links.
> Depending on the privileges of the rsync process, an attacker could leak
> sensitive information, potentially leading to privilege escalation.
> For more details, see the advisory:
> https://www.openwall.com/lists/oss-security/2025/01/14/3
> Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Committed to 2024.02.x and 2024.11.x, thanks.
--
Bye, Peter Korsgaard
_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot
prev parent reply other threads:[~2025-01-22 15:05 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-01-15 16:33 [Buildroot] [PATCH] package/rsync: security bump to version 3.4.0 Peter Korsgaard
2025-01-15 18:34 ` Julien Olivain
2025-01-22 15:05 ` Peter Korsgaard [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=87plkenb26.fsf@dell.be.48ers.dk \
--to=peter@korsgaard.com \
--cc=bernd@kuhls.net \
--cc=buildroot@buildroot.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.