CVE-2011-1097

rsync 3.x before 3.0.8, when certain recursion, deletion, and ownership options are used, allows remote rsync servers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via malformed data.
Severity
UNKNOWN
AV:N/AC:H/Au:N/C:P/I:P/A:P
Atk. Vector
NETWORK
Atk. Complexity
HIGH
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
VendorProductVersion
sambarsync
3.0.0
sambarsync
3.0.1
sambarsync
3.0.2
sambarsync
3.0.3
sambarsync
3.0.4
sambarsync
3.0.5
sambarsync
3.0.6
sambarsync
3.0.7
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
rsync
bullseye
3.2.3-4+deb11u1
fixed
squeeze
no-dsa
bookworm
3.2.7-1
fixed
sid
3.3.0-1
fixed
trixie
3.3.0-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
rsync
maverick
Fixed 3.0.7-2ubuntu1.1
released
lucid
Fixed 3.0.7-1ubuntu1.1
released
karmic
Fixed 3.0.6-1ubuntu1.1
released
hardy
not-affected
dapper
not-affected
References