跳转到帖子

Red Hat OpenShift: CVE-2024-12085: rsync: Info Leak via Uninitialized Stack Contents

recommended_posts

发布于
  • Members

Red Hat OpenShift: CVE-2024-12085: rsync: Info Leak via Uninitialized Stack Contents

Severity
4
CVSS
(AV:L/AC:M/Au:N/C:P/I:P/A:P)
Published
01/14/2025
Created
02/14/2025
Added
02/13/2025
Modified
02/14/2025

Description

A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.

Solution(s)

  • linuxrpm-upgrade-rhcos

References

  • https://attackerkb.com/topics/cve-2024-12085
  • CVE - 2024-12085
  • RHSA-2025:0324
  • RHSA-2025:0325
  • RHSA-2025:0637
  • RHSA-2025:0688
  • RHSA-2025:0714
  • RHSA-2025:0774
  • RHSA-2025:0787
  • RHSA-2025:0790
  • RHSA-2025:0849
  • RHSA-2025:0884
  • RHSA-2025:0885
  • RHSA-2025:1120
  • RHSA-2025:1123
  • RHSA-2025:1128
  • RHSA-2025:1225
  • RHSA-2025:1227
  • RHSA-2025:1242
View more
  • 查看数 701
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。

游客
回帖…