Lucene search

K
cloudlinuxCloudLinuxCLSA-2022:1662658348
HistorySep 08, 2022 - 5:32 p.m.

Fixed CVE-2022-29154 in rsync

2022-09-0817:32:28
repo.cloudlinux.com
26
security update
arbitrary file write
mitm attack
refactoring
test system
unix

7.4 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H

0.001 Low

EPSS

Percentile

41.1%

  • CVE-2022-29154: fix arbitrary file write vulnerability via malicious rsync
    server (MITM attack), refactoring
  • fix test-system components, enable ‘daemon’ and ‘hardlinks’ tests
OSVersionArchitecturePackageVersionFilename
Centos6x86_64rsync< 3.0.6rsync-3.0.6-12.el6.tuxcare.els4.src.rpm

7.4 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H

0.001 Low

EPSS

Percentile

41.1%