Vulnerability Assessment Details

MDKSA-2003:111: rsync

Vulnerability Assessment Summary
Check for the version of the rsync package

Detailed Explanation for this Vulnerability Assessment

The remote host is missing the patch for the advisory MDKSA-2003:111 (rsync).

A vulnerability was discovered in all versions of rsync prior to 2.5.7 that was
recently used in conjunction with the Linux kernel do_brk() vulnerability to
compromise a public rsync server.
This heap overflow vulnerability, by itself, cannot yield root access, however
it does permit arbitrary code execution on the host running rsync as a server.
Also note that this only affects hosts running rsync in server mode (listening
on port 873, typically under xinetd).

Solution :
Network Security Threat Level: High

Networks Security ID:

Vulnerability Assessment Copyright: This script is Copyright (C) 2004 Tenable Network Security

