5.1
CVSSv2

CVE-2011-1097

Published: 30/03/2011 Updated: 13/02/2023
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 454
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

rsync 3.x prior to 3.0.8, when certain recursion, deletion, and ownership options are used, allows remote rsync servers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via malformed data.

Vulnerable Product Search on Vulmon Subscribe to Product

samba rsync 3.0.5

samba rsync 3.0.0

samba rsync 3.0.3

samba rsync 3.0.2

samba rsync 3.0.7

samba rsync 3.0.4

samba rsync 3.0.1

samba rsync 3.0.6

Vendor Advisories

Debian Bug report logs - #621866 rsync: CVE-2011-1097 DoS and possibly code execution on client side Package: rsync; Maintainer for rsync is Paul Slootman <paul@debianorg>; Source for rsync is src:rsync (PTS, buildd, popcon) Reported by: Nico Golde <nion@debianorg> Date: Sat, 9 Apr 2011 20:51:31 UTC Severity: gra ...
rsync could be made to crash or run programs as your login if it connected to a malicious server ...