ZeroHour

CVE-2024-12085

PoC
CVSS 3.1
7.5 high
EPSS
9%p95
Published
()
Modified
Description

A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.

Vendors
sambaredhatalmalinuxarchlinuxgentoonixossusetritondatacenter
Products
rsync, openshift, openshift container platform, enterprise linux, enterprise linux eus, enterprise linux for arm 64, enterprise linux for arm 64 eus, enterprise linux for ibm z systems, enterprise linux for ibm z systems eus, enterprise linux for power little endian, enterprise linux for power little endian eus, enterprise linux server
Weakness
CWE-908
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news