Debian DSA-404-1 : rsync - heap overflow

high Nessus Plugin ID 15241

Synopsis

The remote Debian host is missing a security-related update.

Description

The rsync team has received evidence that a vulnerability in all versions of rsync prior to 2.5.7, a fast remote file copy program, was recently used in combination with a Linux kernel vulnerability to compromise the security of a public rsync server.

While this heap overflow vulnerability could not be used by itself to obtain root access on an rsync server, it could be used in combination with the recently announced do_brk() vulnerability in the Linux kernel to produce a full remote compromise.

Please note that this vulnerability only affects the use of rsync as an 'rsync server'. To see if you are running a rsync server you should use the command 'netstat -a -n' to see if you are listening on TCP port 873. If you are not listening on TCP port 873 then you are not running an rsync server.

Solution

Upgrade the rsync package immediately if you are providing remote sync services. If you are running testing and provide remote sync services please use the packages for woody.

For the stable distribution (woody) this problem has been fixed in version 2.5.5-0.2.

However, since the Debian infrastructure is not yet fully functional after the recent break-in, packages for the unstable distribution are not able to enter the archive for a while. Hence they were placed in Joey's home directory on the security machine.

See Also

http://klecker.debian.org/~joey/rsync/

http://www.debian.org/security/2003/dsa-404

Plugin Details

Severity: High

ID: 15241

File Name: debian_DSA-404.nasl

Version: 1.24

Type: local

Agent: unix

Published: 9/29/2004

Updated: 1/4/2021

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.4

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.2

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: p-cpe:/a:debian:debian_linux:rsync, cpe:/o:debian:debian_linux:3.0

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 12/4/2003

Vulnerability Publication Date: 12/4/2003

Exploitable With

CANVAS (CANVAS)

Reference Information

CVE: CVE-2003-0962

BID: 9153

DSA: 404