Lucene search

K
amazonAmazonALAS2-2022-1873
HistoryOct 31, 2022 - 7:40 p.m.

Important: rsync

2022-10-3119:40:00
alas.aws.amazon.com
30
rsync
server
overwrite
files
vulnerability
man-in-the-middle
exploitation
update
red hat
mitre

7.4 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H

8.7 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

41.3%

Issue Overview:

A flaw was found in rsync that is triggered by a victim rsync user/client connecting to a malicious rsync server. The server can copy and overwrite arbitrary files in the client’s rsync target directory and subdirectories. This flaw allows a malicious server, or in some cases, another attacker who performs a man-in-the-middle attack, to potentially overwrite sensitive files on the client machine, resulting in further exploitation. (CVE-2022-29154)

Affected Packages:

rsync

Note:

This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.

Issue Correction:
Run yum update rsync to update your system.

New Packages:

aarch64:  
    rsync-3.1.2-11.amzn2.0.1.aarch64  
    rsync-debuginfo-3.1.2-11.amzn2.0.1.aarch64  
  
i686:  
    rsync-3.1.2-11.amzn2.0.1.i686  
    rsync-debuginfo-3.1.2-11.amzn2.0.1.i686  
  
src:  
    rsync-3.1.2-11.amzn2.0.1.src  
  
x86_64:  
    rsync-3.1.2-11.amzn2.0.1.x86_64  
    rsync-debuginfo-3.1.2-11.amzn2.0.1.x86_64  

Additional References

Red Hat: CVE-2022-29154

Mitre: CVE-2022-29154

7.4 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H

8.7 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

41.3%