SB2015012304 - Command Injection in lsyncd (Alpine package)
Published: January 23, 2015
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Command Injection (CVE-ID: CVE-2014-8990)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
default-rsyncssh.lua in Lsyncd 2.1.5 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a filename.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=61996bf587870dd0479abad6dddc13de1e09734c
- https://git.alpinelinux.org/aports/commit/?id=6bf81f56e8c0b362d9c5ed046d9a8cdb81d5d957
- https://git.alpinelinux.org/aports/commit/?id=655d521104ae64806748d619c3e3394c4974aa55
- https://git.alpinelinux.org/aports/commit/?id=cf8d2d1f0ae199d0febfc6b95f80b4e071fe2a7e