SUSE Linux Advisory: rsync

Aug 17, 2004, 15:14 (0 Talkback[s])

SUSE Security Announcement

Package: rsync
Announcement-ID: SUSE-SA:2004:026
Date: Monday, Aug 16th 2004 16:00 MEST
Affected products: 8.1, 8.2, 9.0, 9.1 SUSE Linux Database Server, SUSE eMail Server III, 3.1 SUSE Linux Enterprise Server 8, 9 SUSE Linux Firewall on CD/Admin host SUSE Linux Connectivity Server SUSE Linux Office Server
Vulnerability Type: remote system compromise
Severity (1-10): 2
SUSE default package: no
Cross References: http://samba.org/rsync/#security_aug04

1) problem description, brief discussion

The rsync-team released an advisory about a security problem in rsync. If rsync is running in daemon-mode and without a chroot environment it is possible for a remote attacker to trick rsyncd into creating an absolute pathname while sanitizing it. As a result it is possible to read/write from/to files outside the rsync directory.

SUSE LINUX ships the rsync daemon with a chroot environment enabled by default, therefore the default setup is not vulnerable.

2) solution/workaround

As a temporary workaround we suggest to keep the chroot-option of rsyncd enabled or to avoid the daemon-mode and use SSH as transport channel if possible.

3) special instructions and notes

After applying the update, all instances of the rsyncd should be closed and the rsync daemon should be restarted. Please execute the following command as root: 'rcrsyncd restart'

4) package location and checksums

Please download the update package for your distribution and verify its integrity by the methods listed in section 3) of this announcement. Then, install the package using the command "rpm -Fhv file.rpm" to apply the update.
Our maintenance customers are being notified individually. The packages are being offered to install from the maintenance web.

5) Pending vulnerabilities in SUSE Distributions and Workarounds:

  • KDE The KDE libs package contained two occurrences of insecure handling of temporary files in the mcoputils code (Thanks to Andrew Tuitt for reporting this to us) and in the dcopserver code. These two bugs can be exploited locally to remove and/or overwrite files with the privileges of the user running a vulnerable KDE application. A bug in the kdebase3 package allows the content of unrelated browser windows to be modified. This issue may be used to trick users into entering sensitive informations on a malicious web-site. New packages are available on our FTP servers.
  • mozilla/firefox We are currently testing new mozilla/firefox packages that include several fixes for security-related bugs. New packages are available on our FTP servers (for some products we have to delay the delivery of the update package).
  • xine-lib This update of xine fix' a buffer overflow in the vcd input source identifier. This buffer overflow is independent of the media format. The bug can be used to execute arbitrary commands. New packages are available on our FTP servers.
  • opera The web-browser opera is affected by several security bugs. Due to the nature of this package we are not able to provide security updates in a timely manner and have to wait for binary packages to be published by "Opera Software".
  • acroread iDEFENSE reported a buffer overflow and insecure handling of shell meta-chars in acroread code. We depend on the release of a new binary package by Adobe. An update will be available as soon as possible.

