Summary
The remote host is missing an update to rsync
announced via advisory DSA 1545-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%201545-1
Insight
Sebastian Krahmer discovered that an integer overflow in rsync's code for handling extended attributes may lead to arbitrary code execution.
For the stable distribution (etch), this problem has been fixed in version 2.6.9-2etch2.
For the unstable distribution (sid), this problem has been fixed in version 3.0.2-1.
We recommend that you upgrade your rsync package.
Severity
Classification
-
CVE CVE-2008-1720 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities