New issue
Advanced search Search tips

Issue 786699 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Nov 2017
EstimatedDays: ----
NextAction: ----
OS: Chrome
Pri: 1
Type: Bug-Security



Sign in to add a comment

CrOS: Vulnerability reported in net-misc/rsync

Project Member Reported by vomit.go...@appspot.gserviceaccount.com, Nov 18 2017

Issue description

Automated analysis has detected that the following third party packages have had vulnerabilities publicly reported. 

NOTE: There may be several bugs listed below - in almost all cases, all bugs can be quickly addressed by upgrading to the latest version of the package.

Package Name: net-misc/rsync
Package Version: [cpe:/a:samba:rsync:3.1.2]

Advisory: CVE-2017-15994
  Details: https://vomit.googleplex.com/advisory?id=CVE/CVE-2017-15994
  CVSS severity score: 7.5/10.0
  Confidence: high
  Description:

rsync 3.1.3-development before 2017-10-24, as used in the xlucas svfs rsync fork and other products, mishandles archaic checksums, which makes it easier for remote attackers to bypass intended access restrictions.


 
I need to figure out of if this affects Chrome OS. The CVE message is confusing:
rsync 3.1.3-development before 2017-10-24, as used in the xlucas svfs rsync fork and other products, mishandles archaic checksums, which makes it easier for remote attackers to bypass intended access restrictions.

Did this affect 3.1.2 or not? 
Project Member

Comment 3 by sheriffbot@chromium.org, Mar 6 2018

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment