Alpine: multiple rrsync packages: security update to 3.1.2-r6 (deprecated)

critical Tenable Self-Hosted Container Security Plugin ID 400760

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- The receive_xattr function in xattrs.c in rsync 3.1.2 and 3.1.3-development does not check for a trailing
'\0' character in an xattr name, which allows remote attackers to cause a denial of service (heap-based
buffer over-read and application crash) or possibly have unspecified other impact by sending crafted data
to the daemon. (CVE-2017-16548)

- The recv_files function in receiver.c in the daemon in rsync 3.1.2, and 3.1.3-development before
2017-12-03, proceeds with certain file metadata updates before checking for a filename in the
daemon_filter_list data structure, which allows remote attackers to bypass intended access restrictions.
(CVE-2017-17433)

- The daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, does not check for fnamecmp filenames
in the daemon_filter_list data structure (in the recv_files function in receiver.c) and also does not
apply the sanitize_paths protection mechanism to pathnames found in "xname follows" strings (in the
read_ndx_and_attrs function in rsync.c), which allows remote attackers to bypass intended access
restrictions. (CVE-2017-17434)

See Also

https://git.alpinelinux.org/aports/commit/?id=48060cb2416c23c814120b087b8650c01e195446

https://git.alpinelinux.org/aports/commit/?id=80540c1d0ea805c1cff515df8e120ad20dc8a0a2

Plugin Details

Severity: Critical

ID: 400760

Version: Revision 1.24

Type: Local

Published: 8/16/2023

Updated: 9/20/2024

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.15

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2017-17434

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 12/29/2017

Vulnerability Publication Date: 11/6/2017

Reference Information

CVE: CVE-2017-16548, CVE-2017-17433, CVE-2017-17434