{"id":"SUSE-SU-2018:0117-1","summary":"Security update for rsync","details":"This update for rsync fixes the following issues:\n\nSecurity issues fixed:\n\n- CVE-2017-17434: The daemon in rsync did not check for fnamecmp filenames in\n  the daemon_filter_list data structure (in the recv_files function in\n  receiver.c) and also did not apply the sanitize_paths protection mechanism to\n  pathnames found in 'xname follows' strings (in the read_ndx_and_attrs function\n  in rsync.c), which allowed remote attackers to bypass intended access\n  restrictions' (bsc#1071460).\n- CVE-2017-17433: The recv_files function in receiver.c in the daemon in rsync,\n  proceeded with certain file metadata updates before checking for a filename in\n  the daemon_filter_list data structure, which allowed remote attackers to bypass\n  intended access restrictions (bsc#1071459).\n- CVE-2017-16548: The receive_xattr function in xattrs.c in rsync did not check\n  for a trailing '\\\\0' character in an xattr name, which allowed remote attackers\n  to cause a denial of service (heap-based buffer over-read and application\n  crash) or possibly have unspecified other impact by sending crafted data to the\n  daemon (bsc#1066644).\n","modified":"2026-03-11T06:39:08.559907Z","published":"2018-01-17T07:32:49Z","related":["CVE-2017-16548","CVE-2017-17433","CVE-2017-17434"],"upstream":["CVE-2017-16548","CVE-2017-17433","CVE-2017-17434"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2018/suse-su-20180117-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1066644"},{"type":"REPORT","url":"https://bugzilla.suse.com/1071459"},{"type":"REPORT","url":"https://bugzilla.suse.com/1071460"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-16548"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-17433"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-17434"}],"affected":[{"package":{"name":"rsync","ecosystem":"SUSE:Linux Enterprise Server 11 SP4","purl":"pkg:rpm/suse/rsync&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.0.4-2.53.3.1"}]}],"ecosystem_specific":{"binaries":[{"rsync":"3.0.4-2.53.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2018:0117-1.json"}},{"package":{"name":"rsync","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 11 SP4","purl":"pkg:rpm/suse/rsync&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.0.4-2.53.3.1"}]}],"ecosystem_specific":{"binaries":[{"rsync":"3.0.4-2.53.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2018:0117-1.json"}}],"schema_version":"1.7.5"}