oss-sec mailing list archives
Re: Re: CVE request: lsyncd command injection
From: Michael Samuel <mik () miknet net>
Date: Fri, 21 Nov 2014 22:24:21 +1100
On 20 November 2014 17:55, <cve-assign () mitre org> wrote:
Use CVE-2014-8990. The scope of this CVE ID includes both: 2. denial of service scenarios in which a user with write access to a local directory uses special characters to make synchronization fail (might have security relevance in some scenarios)
Note that you can still make synchronization fail, because it calls rsync to perform the synchronization. See https://github.com/therealmik/rsync-collision for some precomputed blocks Regards, Michael
Current thread:
- CVE request: lsyncd command injection Murray McAllister (Nov 18)
- Re: CVE request: lsyncd command injection cve-assign (Nov 19)
- Re: Re: CVE request: lsyncd command injection Michael Samuel (Nov 21)
- Re: Re: CVE request: lsyncd command injection Ángel González (Nov 25)
- Re: Re: CVE request: lsyncd command injection Sven Schwedas (Nov 26)
- Re: CVE request: lsyncd command injection cve-assign (Nov 19)