oss-sec mailing list archives

Re: Re: [CVE Requests] rsync and librsync collisions


From: Michael Samuel <mik () miknet net>
Date: Sat, 11 Apr 2015 12:04:58 +1000

On 11 April 2015 at 06:19, mancha <mancha1 () zoho com> wrote:
* Dne Thursday 18. September 2014, 04:30:22 [CEST] Michael Samuel napsal:
Ok, for rsync you can download colliding blocks (and a brief description) here:

https://github.com/therealmik/rsync-collision

The last time this was discussed it was suggested to the reporter that a
fully working PoC be posted so the impact (or lack thereof) to rsync
might be evaluated.

Unless I missed it, this hasn't happened.

I reported it upstream with full working PoC

Regards,
  Michael


Current thread: