Family: Mandrake Local Security Checks --> Category: infos
MDKSA-2003:111: rsync Vulnerability Scan
Vulnerability Scan Summary
Check for the version of the rsync package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory MDKSA-2003:111 (rsync).
A vulnerability was discovered in all versions of rsync prior to 2.5.7 that was
recently used in conjunction with the Linux kernel do_brk() vulnerability to
compromise a public rsync server.
This heap overflow vulnerability, by itself, cannot yield root access, however
it does allow arbitrary code execution on the host running rsync as a server.
Also note that this only affects hosts running rsync in server mode (listening
on port 873, typically under xinetd).
Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2003:111
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.