rsync-2.5.2 has security fix (was: Re: [RHSA-2002:018-05] New rsync packages available)

From: Jim Knoble (jmknoble@pobox.com)
Date: 01/27/02


Date: Sun, 27 Jan 2002 04:45:41 -0500
From: Jim Knoble <jmknoble@pobox.com>
To: redhat-watch-list@redhat.com, bugtraq@securityfocus.com


Circa 2002-Jan-25 16:33:00 -0500 dixit bugzilla@redhat.com:

: ---------------------------------------------------------------------
: Red Hat, Inc. Red Hat Security Advisory
:
: Synopsis: New rsync packages available
: Advisory ID: RHSA-2002:018-05
: Issue date: 2002-01-23
: Updated on: 2002-01-25
: Product: Red Hat Linux
: Keywords: rsync signed unsigned daemon
: Cross references:
: Obsoletes:
: ---------------------------------------------------------------------
:
: 1. Topic:
:
: New rsync packages are available; these fix a remotely exploitable problem
: in the I/O functions.

  [...]

: rsync is a powerful tool used for mirroring directory structures across
: machines. rsync has been found to contain several signed/unsigned bugs in
: its I/O functions which are remotely exploitable. A remote user can crash
: the rsync server/client and execute code as the user running the rsync
: server or client.
:
: The Common Vulnerabilities and Exposures project (cve.mitre.org) has
: assigned the name CAN-2002-0048 to this issue.

I can't seem to find any information about this issue at cve.mitre.org;
it simply says:

  ** RESERVED ** This candidate has been reserved by an organization or
  individual that will use it when announcing a new security problem.
  When the candidate has been publicized, the details for this
  candidate will be provided.

I've seen at least three announcements about rsync from different Linux
distribution vendors, but no information at all about what versions are
actually vulnerable, or when the vulnerability was discovered (or fixed).

For folks who have actually moved beyond vendor-supplied
point-and-drool packages of rsync, there's a need for actual real
information about what versions of rsync are vulnerable and what the
fix is.

Hence, this news from http://rsync.samba.org/:

    rsync 2.5.2

             The latest version of rsync is version 2.5.2.

             This version includes the following changes:

             rsync 2.5.2 (26 Jan 2002)

               SECURITY FIXES:

                 * Signedness security patch from Sebastian Krahmer
                    -- in some cases we were not sufficiently
                   careful about reading integers from the network.

Further information is at http://rsync.samba.org/.

I find it tiring that vendors neglect to disclose this sort of
information in their public announcements. A simple statement such as
"Plain-vanilla versions of rsync less than 2.5.2 are vulnerable.
However, we've backported the fix to our sparkling new package of
rsync-2.4.6. Customers who use our Strawberry Linux Forever
distribution should upgrade to our packages, listed below: ...."

That sort of information helps everyone.

--
jim knoble | jmknoble@pobox.com   | http://www.pobox.com/~jmknoble/
(GnuPG fingerprint: 31C4:8AAC:F24E:A70C:4000::BBF4:289F:EAA8:1381:1491)




Relevant Pages

  • [Full-Disclosure] SUSE Security Announcement: rsync (SuSE-SA:2003:050)
    ... In most private networks the rsync client tool is used via SSH to fulfill ... In an open environment rsync is run in server mode accepting ... after December 15th 2003 will not be fixed any more for SuSE Linux ... New KDE packages are currently being tested. ...
    (Full-Disclosure)
  • Re: apt-get/aptitude update failing [solved]
    ... a patched older release of rsync, and things may improve in the ... Between Nathan's fix and upgrading to aptitude 0.4.2, ... nor problems trying to download packages. ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)
  • SUSE Security Announcement: rsync (SuSE-SA:2003:050)
    ... In most private networks the rsync client tool is used via SSH to fulfill ... In an open environment rsync is run in server mode accepting ... after December 15th 2003 will not be fixed any more for SuSE Linux ... New KDE packages are currently being tested. ...
    (Bugtraq)
  • [CLA-2003:794] Conectiva Security Announcement - rsync
    ... rsync versions prior to 2.5.7 have a heap buffer overflow ... This vulnerability specially affects installations where rsync is ... It is recommended that all rsync users upgrade their packages. ... Detailed instructions reagarding the use of apt and upgrade examples ...
    (Bugtraq)
  • [CLA-2002:458] Conectiva Linux Security Announcement - rsync
    ... "rsync" is a program used mainly to mirror files between remote ... It is recommended that all rsync users upgrade their packages. ... Detailed instructions reagarding the use of apt and upgrade examples ...
    (Bugtraq)