CVE-2014-2855

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
23/04/2014
Last modified:
12/04/2025

Description

The check_secret function in authenticate.c in rsync 3.1.0 and earlier allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a user name which does not exist in the secrets file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:samba:rsync:*:*:*:*:*:*:*:* 3.1.0 (including)
cpe:2.3:a:samba:rsync:2.6.9:*:*:*:*:*:*:*
cpe:2.3:a:samba:rsync:2.7.0:*:*:*:*:*:*:*
cpe:2.3:a:samba:rsync:2.7.1:*:*:*:*:*:*:*
cpe:2.3:a:samba:rsync:2.7.2:*:*:*:*:*:*:*
cpe:2.3:a:samba:rsync:2.7.3:*:*:*:*:*:*:*
cpe:2.3:a:samba:rsync:2.7.4:*:*:*:*:*:*:*
cpe:2.3:a:samba:rsync:2.7.5:*:*:*:*:*:*:*
cpe:2.3:a:samba:rsync:2.7.6:*:*:*:*:*:*:*
cpe:2.3:a:samba:rsync:2.7.7:*:*:*:*:*:*:*
cpe:2.3:a:samba:rsync:2.7.8:*:*:*:*:*:*:*
cpe:2.3:a:samba:rsync:2.7.9:*:*:*:*:*:*:*
cpe:2.3:a:samba:rsync:2.8.0:*:*:*:*:*:*:*
cpe:2.3:a:samba:rsync:2.8.1:*:*:*:*:*:*:*
cpe:2.3:a:samba:rsync:2.8.2:*:*:*:*:*:*:*