CVE Vulnerabilities

CVE-2014-8242

Published: Oct 26, 2015 | Modified: May 19, 2020
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW

librsync before 1.0.0 uses a truncated MD4 checksum to match blocks, which makes it easier for remote attackers to modify transmitted data via a birthday attack.

Affected Software

Name Vendor Start Version End Version
Librsync Librsync_project * 1.0.0 (excluding)
Librsync Ubuntu artful *
Librsync Ubuntu bionic *
Librsync Ubuntu cosmic *
Librsync Ubuntu disco *
Librsync Ubuntu esm-infra/bionic *
Librsync Ubuntu esm-infra/xenial *
Librsync Ubuntu lucid *
Librsync Ubuntu precise *
Librsync Ubuntu trusty *
Librsync Ubuntu utopic *
Librsync Ubuntu vivid *
Librsync Ubuntu wily *
Librsync Ubuntu xenial *
Librsync Ubuntu yakkety *
Librsync Ubuntu zesty *

References