CVE-2024-12084 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in th…
Critical CVSS: 9.8

CVE-2024-12084

A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), an attacker can write out of bounds in the sum2 buffer.
Vendor
Samba
Product
Rsync
CWE
CWE-122
Yayın Tarihi
2025-01-15 15:15:10
Güncelleme
2025-11-03 22:16:38
Source Identifier
secalert@redhat.com
KEV Date Added
-

Kategoriler

Referanslar