==========================================================================
Ubuntu Security Notice USN-2171-1
April 23, 2014
rsync vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
– Ubuntu 14.04 LTS
Summary:
rsync could be made to consume resources if it received specially crafted
network traffic.
Software Description:
– rsync: fast, versatile, remote (and local) file-copying tool
Details:
Ryan Finnie discovered that the rsync daemon incorrectly handled invalid
usernames. A remote attacker could use this issue to cause rsync to consume
resources, resulting in a denial of service.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 14.04 LTS:
rsync 3.1.0-2ubuntu0.1
In general, a standard system update will make all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2171-1
CVE-2014-2855
Package Information:
https://launchpad.net/ubuntu/+source/rsync/3.1.0-2ubuntu0.1
—–BEGIN PGP SIGNATURE—–
Version: GnuPG v1
Comment: Using GnuPG with Thunderbird – http://www.enigmail.net/
iQIcBAEBCgAGBQJTV9LaAAoJEGVp2FWnRL6TSrMP/0SbVaUV6VuHpobhFcF5046l
X5HSgh5zMWNCUIeISaTfHEF4v89WZ0dSnosLU9ovqf9zmv6O96Vb3iBH3oMtEnDG
dVaVWmeix4Nam6WogCgeQzvFxDFdq0JNt5Q0PuOBCIgkn2tQXDiXDeNgPBj/B4bs
VdrgHL3q7qCa1s74vxwvQdyywl1CW7Yu/GwwxvReAMK3/ZlJOKDLnUMC4q+CuVtW
YwrgetLgS+ll29ngykGEEwf4kUKFJNV07UFx9qyGrQN8Ohn8hTVrts5gQ7X4hVMe
5yRNPoVHPAVcqExjAKWzFCfTnRjo0Y9a9sOY7Vxe9d/KSlWjgK9nQT1Hqtg58use
Ksx6WmuNhf2knYXhui2l4kvl0RDxBveA9usLL+6K5+5pUX98zCIXkI53wr8iIVc3
XR9a29w+LdliBo5WYWGvD972iMbbOBFVQt9boM8jroDiI5iKuqEc619DHshVevP6
XbraUvUX78ZuGfJhYv+X0NL/6i1Gv3+LrHseU1KLgm6Du5Mwa7aR0/VkYi6PtkQF
HhMU144RXgbeEb6valD/oXbqexfrVRva9NMSZx1QEAYxfVmZ+XfsTHYU6jknifmE
egRI1BFNxuQ6zSa3bjZwKO8ReAWGbWyXLHU39dVRLzKPSk+Xyn30tblWnwed2jZg
Y5Shiv98dH+45DM4w5uY
=t6D1
—–END PGP SIGNATURE—–
—