MGASA-2015-0065
Dashboard / Vulnerabilities / MGASA-2015-0065
Summary: Updated rsync package fixes security vulnerability
Details: Updated rsync package fixes security vulnerability: Ryan Finnie discovered that rsync 3.1.0 contains a denial of service issue when attempting to authenticate using a nonexistent username. A remote attacker could use this flaw to cause a denial of service via CPU consumption (CVE-2014-2855). The previous update for this issue in MGASA-2014-0179 failed to properly apply the needed patch, so the package has been rebuilt to address this issue.
References: https://advisories.mageia.org/MGASA-2015-0065.html, https://bugs.mageia.org/show_bug.cgi?id=13214, http://openwall.com/lists/oss-security/2014/04/15/1, http://advisories.mageia.org/MGASA-2014-0179.html
Affected packages
Package
Name: rsync
Purl: pkg:rpm/mageia/rsync?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
