VDB

GCVE-110-MAGEIA-2020-108

GCVE-110-MAGEIA-2020-108
Advisory Published
Vulnetix · Advisory published February 29, 2020
Updated rsync packages fix security vulnerabilities: It was discovered that rsync incorrectly handled pointer arithmetic in zlib. An attacker could use this issue to cause rsync to crash, resulting in a denial of service, or possibly execute arbitrary code (CVE-2016-9840, CVE-2016-9841) It was discovered that rsync incorrectly handled vectors involving left shifts of negative integers in zlib. An attacker could use this issue to cause rsync to crash, resulting in a denial of service, or possibly execute arbitrary code (CVE-2016-9842). It was discovered that rsync incorrectly handled vectors involving big- endian CRC calculation in zlib. An attacker could use this issue to cause rsync to crash, resulting in a denial of service, or possibly execute arbitrary code (CVE-2016-9843). Please note, we now compile against system zlib. If rsync fails to sync with older remote systems using compression (-z), you have either update the remote host to a newer version or disable compression.

Affected Products

VendorProductVersionsPlatforms
Mageiarsync0 (affected), 3.1.3-4.mga7 (unaffected), 0 (affected), 3.1.3-4.mga7 (unaffected)
Mageianvidia340340.108-6.mga7.nonfree (unaffected), 0 (affected)

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›