First published: Fri Feb 04 2011(Updated: )
rsync 3.x before 3.0.8, when certain recursion, deletion, and ownership options are used, allows remote rsync servers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via malformed data.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samba | =3.0.5 | |
Samba | =3.0.0 | |
Samba | =3.0.3 | |
Samba | =3.0.2 | |
Samba | =3.0.7 | |
Samba | =3.0.4 | |
Samba | =3.0.1 | |
Samba | =3.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1097 has a severity that can lead to denial of service and potential remote code execution.
To fix CVE-2011-1097, upgrade rsync to version 3.0.8 or later.
CVE-2011-1097 affects rsync versions prior to 3.0.8, including versions 3.0.0 through 3.0.7.
The potential impacts of CVE-2011-1097 include application crashes and remote code execution vulnerabilities.
CVE-2011-1097 was identified by Wayne Davison and others regarding memory safety issues.