CVE-2008-1720

Buffer overflow in rsync 2.6.9 to 3.0.1, with extended attribute (xattr) support enabled, might allow remote attackers to execute arbitrary code via unknown vectors.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:samba:rsync:2.6.9:*:*:*:*:*:*:*
cpe:2.3:a:samba:rsync:2.7.0:*:*:*:*:*:*:*
cpe:2.3:a:samba:rsync:2.7.1:*:*:*:*:*:*:*
cpe:2.3:a:samba:rsync:2.7.2:*:*:*:*:*:*:*
cpe:2.3:a:samba:rsync:2.7.3:*:*:*:*:*:*:*
cpe:2.3:a:samba:rsync:2.7.4:*:*:*:*:*:*:*
cpe:2.3:a:samba:rsync:2.7.5:*:*:*:*:*:*:*
cpe:2.3:a:samba:rsync:2.7.6:*:*:*:*:*:*:*
cpe:2.3:a:samba:rsync:2.7.7:*:*:*:*:*:*:*
cpe:2.3:a:samba:rsync:2.7.8:*:*:*:*:*:*:*
cpe:2.3:a:samba:rsync:2.7.9:*:*:*:*:*:*:*
cpe:2.3:a:samba:rsync:2.8.0:*:*:*:*:*:*:*
cpe:2.3:a:samba:rsync:2.8.1:*:*:*:*:*:*:*
cpe:2.3:a:samba:rsync:2.8.2:*:*:*:*:*:*:*
cpe:2.3:a:samba:rsync:2.8.3:*:*:*:*:*:*:*
cpe:2.3:a:samba:rsync:2.8.4:*:*:*:*:*:*:*
cpe:2.3:a:samba:rsync:2.8.5:*:*:*:*:*:*:*
cpe:2.3:a:samba:rsync:2.8.6:*:*:*:*:*:*:*
cpe:2.3:a:samba:rsync:2.8.7:*:*:*:*:*:*:*
cpe:2.3:a:samba:rsync:2.8.8:*:*:*:*:*:*:*
cpe:2.3:a:samba:rsync:2.8.9:*:*:*:*:*:*:*
cpe:2.3:a:samba:rsync:2.9.0:*:*:*:*:*:*:*
cpe:2.3:a:samba:rsync:2.9.1:*:*:*:*:*:*:*
cpe:2.3:a:samba:rsync:2.9.2:*:*:*:*:*:*:*
cpe:2.3:a:samba:rsync:2.9.3:*:*:*:*:*:*:*
cpe:2.3:a:samba:rsync:2.9.4:*:*:*:*:*:*:*
cpe:2.3:a:samba:rsync:2.9.5:*:*:*:*:*:*:*
cpe:2.3:a:samba:rsync:2.9.6:*:*:*:*:*:*:*
cpe:2.3:a:samba:rsync:2.9.7:*:*:*:*:*:*:*
cpe:2.3:a:samba:rsync:2.9.8:*:*:*:*:*:*:*
cpe:2.3:a:samba:rsync:2.9.9:*:*:*:*:*:*:*
cpe:2.3:a:samba:rsync:3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:samba:rsync:3.0.1:*:*:*:*:*:*:*

History

13 Feb 2023, 02:19

Type Values Removed Values Added
Summary CVE-2008-1720 rsync: integer overflow in xattr handling Buffer overflow in rsync 2.6.9 to 3.0.1, with extended attribute (xattr) support enabled, might allow remote attackers to execute arbitrary code via unknown vectors.
References
  • {'url': 'https://bugzilla.redhat.com/show_bug.cgi?id=441683', 'name': 'https://bugzilla.redhat.com/show_bug.cgi?id=441683', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/security/cve/CVE-2008-1720', 'name': 'https://access.redhat.com/security/cve/CVE-2008-1720', 'tags': [], 'refsource': 'MISC'}

02 Feb 2023, 17:15

Type Values Removed Values Added
References
  • {'url': 'http://www.mail-archive.com/rsync-announce@lists.samba.org/msg00057.html', 'name': '[rsync-announce] 20080408 Rsync 3.0.2 released w/xattr security fix (attn: 2.6.9 onward)', 'tags': [], 'refsource': 'MLIST'}
  • (MISC) http://www.mail-archive.com/rsync-announce%40lists.samba.org/msg00057.html -
  • (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=441683 -
  • (MISC) https://access.redhat.com/security/cve/CVE-2008-1720 -
Summary Buffer overflow in rsync 2.6.9 to 3.0.1, with extended attribute (xattr) support enabled, might allow remote attackers to execute arbitrary code via unknown vectors. CVE-2008-1720 rsync: integer overflow in xattr handling

Information

Published : 2008-04-10 19:05

Updated : 2023-12-10 10:51


NVD link : CVE-2008-1720

Mitre link : CVE-2008-1720

CVE.ORG link : CVE-2008-1720


JSON object : View

Products Affected

samba

  • rsync
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer