7.5
CVSSv2

CVE-2006-2083

Published: 28/04/2006 Updated: 20/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Integer overflow in the receive_xattr function in the extended attributes patch (xattr.c) for rsync prior to 2.6.8 might allow malicious users to execute arbitrary code via crafted extended attributes that trigger a buffer overflow.

Vulnerable Product Search on Vulmon Subscribe to Product

andrew tridgell rsync 2.6.3

andrew tridgell rsync 2.6.4

andrew tridgell rsync 2.6.7

andrew tridgell rsync 2.6.0

andrew tridgell rsync 2.6.1

andrew tridgell rsync 2.6.2

andrew tridgell rsync 2.6.5

andrew tridgell rsync 2.6.6

Vendor Advisories

Debian Bug report logs - #365614 rsync: Integer overflow in the receive_xattr function (remote exploit) Package: rsync; Maintainer for rsync is Paul Slootman <paul@debianorg>; Source for rsync is src:rsync (PTS, buildd, popcon) Reported by: Jay Kline <jay@ahpcrcorg> Date: Mon, 1 May 2006 14:48:18 UTC Severity: gr ...