CVE-2008-1720: Buffer Overflow
Published Apr 10, 2008
·Updated
Buffer overflow in rsync 2.6.9 to 3.0.1, with extended attribute (xattr) support enabled, might allow remote attackers to execute arbitrary code via unknown vectors.
Affected Software
33 affected components
samba rsync=2.6.9
samba rsync=2.7.0
samba rsync=2.7.1
samba rsync=2.7.2
samba rsync=2.7.3
samba rsync=2.7.4
samba rsync=2.7.5
samba rsync=2.7.6
samba rsync=2.7.7
samba rsync=2.7.8
samba rsync=2.7.9
samba rsync=2.8.0
samba rsync=2.8.1
samba rsync=2.8.2
samba rsync=2.8.3
samba rsync=2.8.4
samba rsync=2.8.5
samba rsync=2.8.6
samba rsync=2.8.7
samba rsync=2.8.8
samba rsync=2.8.9
samba rsync=2.9.0
samba rsync=2.9.1
samba rsync=2.9.2
samba rsync=2.9.3
samba rsync=2.9.4
samba rsync=2.9.5
samba rsync=2.9.6
samba rsync=2.9.7
samba rsync=2.9.8
samba rsync=2.9.9
samba rsync=3.0.0
samba rsync=3.0.1
Remediation
Patch Available
Event History
Apr 10, 2008
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-1720?
CVE-2008-1720 is considered a high-severity vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2008-1720?
To fix CVE-2008-1720, upgrade your rsync software to version 3.0.2 or later.
3
Which versions of rsync are affected by CVE-2008-1720?
CVE-2008-1720 affects rsync versions 2.6.9 to 3.0.1 with extended attribute support enabled.
4
What can attackers do exploiting CVE-2008-1720?
Attackers exploiting CVE-2008-1720 may execute arbitrary code on the affected system.
5
Is CVE-2008-1720 related to any other vulnerabilities?
CVE-2008-1720 is a specific buffer overflow vulnerability in rsync but may share characteristics with other buffer overflow vulnerabilities.