{"affected":[{"ecosystem_specific":{"binaries":[{"rsync":"3.0.4-2.53.3.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 11 SP4","name":"rsync","purl":"pkg:rpm/suse/rsync&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"3.0.4-2.53.3.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"rsync":"3.0.4-2.53.3.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 11 SP4","name":"rsync","purl":"pkg:rpm/suse/rsync&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"3.0.4-2.53.3.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for rsync fixes the following issues:\n\nSecurity issues fixed:\n\n- CVE-2017-17434: The daemon in rsync did not check for fnamecmp filenames in\n  the daemon_filter_list data structure (in the recv_files function in\n  receiver.c) and also did not apply the sanitize_paths protection mechanism to\n  pathnames found in 'xname follows' strings (in the read_ndx_and_attrs function\n  in rsync.c), which allowed remote attackers to bypass intended access\n  restrictions' (bsc#1071460).\n- CVE-2017-17433: The recv_files function in receiver.c in the daemon in rsync,\n  proceeded with certain file metadata updates before checking for a filename in\n  the daemon_filter_list data structure, which allowed remote attackers to bypass\n  intended access restrictions (bsc#1071459).\n- CVE-2017-16548: The receive_xattr function in xattrs.c in rsync did not check\n  for a trailing '\\\\0' character in an xattr name, which allowed remote attackers\n  to cause a denial of service (heap-based buffer over-read and application\n  crash) or possibly have unspecified other impact by sending crafted data to the\n  daemon (bsc#1066644).\n","id":"SUSE-SU-2018:0117-1","modified":"2018-01-17T07:32:49Z","published":"2018-01-17T07:32:49Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2018/suse-su-20180117-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1066644"},{"type":"REPORT","url":"https://bugzilla.suse.com/1071459"},{"type":"REPORT","url":"https://bugzilla.suse.com/1071460"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-16548"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-17433"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-17434"}],"related":["CVE-2017-16548","CVE-2017-17433","CVE-2017-17434"],"summary":"Security update for rsync","upstream":["CVE-2017-16548","CVE-2017-17433","CVE-2017-17434"]}