oss-sec mailing list archives

Re: Re: CVE request: lsyncd command injection


From: Michael Samuel <mik () miknet net>
Date: Fri, 21 Nov 2014 22:24:21 +1100

On 20 November 2014 17:55,  <cve-assign () mitre org> wrote:
Use CVE-2014-8990. The scope of this CVE ID includes both:
  2. denial of service scenarios in which a user with write access
     to a local directory uses special characters to make
     synchronization fail (might have security relevance in some
     scenarios)

Note that you can still make synchronization fail, because it calls
rsync to perform the synchronization.

See https://github.com/therealmik/rsync-collision for some precomputed blocks

Regards,
  Michael


Current thread: