A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), an attacker can write out of bounds in the sum2 buffer.
References
Configurations
No configuration.
History
26 Feb 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
References |
|
15 Jan 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-01-15 15:15
Updated : 2025-02-26 14:15
NVD link : CVE-2024-12084
Mitre link : CVE-2024-12084
CVE.ORG link : CVE-2024-12084
JSON object : View
Products Affected
No product.
CWE
CWE-122
Heap-based Buffer Overflow