Lucene search

K
ubuntucveUbuntu.comUB:CVE-2014-8242
HistoryOct 26, 2015 - 12:00 a.m.

CVE-2014-8242

2015-10-2600:00:00
ubuntu.com
ubuntu.com
10

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:P/A:P

EPSS

0.007

Percentile

79.9%

librsync before 1.0.0 uses a truncated MD4 checksum to match blocks, which
makes it easier for remote attackers to modify transmitted data via a
birthday attack.

Bugs

Notes

Author Note
ebarretto Too intrusive to backport
OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchlibrsync< anyUNKNOWN
ubuntu16.04noarchlibrsync< anyUNKNOWN

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:P/A:P

EPSS

0.007

Percentile

79.9%