First published: Fri Apr 28 2006(Updated: )
Integer overflow in the receive_xattr function in the extended attributes patch (xattr.c) for rsync before 2.6.8 might allow attackers to execute arbitrary code via crafted extended attributes that trigger a buffer overflow.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Rsync | =2.6.0 | |
Rsync | =2.6.1 | |
Rsync | =2.6.2 | |
Rsync | =2.6.3 | |
Rsync | =2.6.4 | |
Rsync | =2.6.5 | |
Rsync | =2.6.6 | |
Rsync | =2.6.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-2083 has a high severity rating due to the potential for arbitrary code execution by attackers.
To mitigate CVE-2006-2083, upgrade to rsync version 2.6.8 or later.
CVE-2006-2083 affects rsync versions prior to 2.6.8, specifically versions 2.6.0 to 2.6.7.
CVE-2006-2083 is an integer overflow vulnerability that can lead to a buffer overflow.
Attackers with the ability to send crafted extended attributes can exploit CVE-2006-2083.