Oval Definition:oval:com.redhat.rhsa:def:20110390
Revision Date:2011-03-28Version:638
Title:RHSA-2011:0390: rsync security update (Moderate)
Description:rsync is a program for synchronizing files over a network.

  • A memory corruption flaw was found in the way the rsync client processed malformed file list data. If an rsync client used the "--recursive" and "--delete" options without the "--owner" option when connecting to a malicious rsync server, the malicious server could cause rsync on the client system to crash or, possibly, execute arbitrary code with the privileges of the user running rsync. (CVE-2011-1097)

    Red Hat would like to thank Wayne Davison and Matt McCutchen for reporting this issue.

    Users of rsync should upgrade to this updated package, which contains a backported patch to resolve this issue.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2011-1097
    CVE-2011-1097
    RHSA-2011:0390
    RHSA-2011:0390-01
    RHSA-2011:0390-01
    Platform(s):Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND rsync is earlier than 0:3.0.6-5.el6_0.1
  • AND rsync is signed with Red Hat redhatrelease2 key
  • BACK