CVE-2017-15994

critical
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

rsync 3.1.3-development before 2017-10-24 mishandles archaic checksums, which makes it easier for remote attackers to bypass intended access restrictions. NOTE: the rsync development branch has significant use beyond the rsync developers, e.g., the code has been copied for use in various GitHub projects.

References

https://git.samba.org/?p=rsync.git;a=commit;h=7b8a4ecd6ff9cdf4e5d3850ebf822f1e989255b3

https://git.samba.org/?p=rsync.git;a=commit;h=9a480deec4d20277d8e20bc55515ef0640ca1e55

https://git.samba.org/?p=rsync.git;a=commit;h=c252546ceeb0925eb8a4061315e3ff0a8c55b48b

Details

Source: MITRE

Published: 2017-10-29

Updated: 2019-10-03

Type: CWE-354

Risk Information

CVSS v2

Base Score: 7.5

Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 10

Severity: HIGH

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 3.9

Severity: CRITICAL

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:samba:rsync:*:*:*:*:*:*:*:* versions up to 3.1.2 (inclusive)

Tenable Plugins

View all (3 total)

IDNameProductFamilySeverity
135659EulerOS Virtualization 3.0.2.2 : rsync (EulerOS-SA-2020-1497)NessusHuawei Local Security Checks
critical
134546EulerOS Virtualization for ARM 64 3.0.2.0 : rsync (EulerOS-SA-2020-1257)NessusHuawei Local Security Checks
critical
129183EulerOS 2.0 SP5 : rsync (EulerOS-SA-2019-1989)NessusHuawei Local Security Checks
critical