Description

A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), an attacker can write out of bounds in the sum2 buffer.

INFO

Published Date :

2025-01-15T14:16:35.363Z

Last Modified :

2026-02-26T19:09:06.939Z

Source :

redhat
AFFECTED PRODUCTS

The following products are affected by CVE-2024-12084 vulnerability.

Vendors Products
Almalinux
  • Almalinux
Archlinux
  • Arch Linux
Gentoo
  • Linux
Nixos
  • Nixos
Novell
  • Suse Linux
Redhat
  • Enterprise Linux
  • Openshift
Samba
  • Rsync
Tritondatacenter
  • Smartos

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact