Oval Definition:oval:com.redhat.rhsa:def:20030399
Revision Date:2003-12-04Version:502
Title:RHSA-2003:399: rsync security update (Critical)
Description:rsync is a program for sychronizing files over the network.

A heap overflow bug exists in rsync versions prior to 2.5.7. On machines where the rsync server has been enabled, a remote attacker could use this flaw to execute arbitrary code as an unprivileged user. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2003-0962 to this issue.

All users should upgrade to these erratum packages containing version 2.5.7 of rsync, which is not vulnerable to this issue.

NOTE: The rsync server is disabled (off) by default in Red Hat Enterprise Linux. To check if the rsync server has been enabled (on), run the following command:

/sbin/chkconfig --list rsync

If the rsync server has been enabled but is not required, it can be disabled by running the following command as root:

/sbin/chkconfig rsync off

Red Hat would like to thank the rsync team for their rapid response and quick fix for this issue.
Family:unixClass:patch
Status:Reference(s):CVE-2003-0962
RHSA-2003:399-01
Platform(s):Red Hat Enterprise Linux 3
Product(s):
Definition Synopsis
  • Red Hat Enterprise Linux 3 is installed
  • AND rsync is earlier than 0:2.5.7-1
  • AND rsync is signed with Red Hat master key
  • BACK