Ubuntu 9.10 / 10.04 LTS / 10.10 : rsync vulnerability (USN-1124-1)
Medium Nessus Plugin ID 55084
SynopsisThe remote Ubuntu host is missing a security-related patch.
DescriptionIt was discovered that rsync incorrectly handled memory when certain recursion, deletion and ownership options were used. If a user were tricked into connecting to a malicious server, a remote attacker could cause a denial of service or execute arbitrary code with privileges of the user invoking the program.
Note that Tenable Network Security has extracted the preceding description block directly from the Ubuntu security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
SolutionUpdate the affected rsync package.