CVE-2024-12085 - log back

CVE-2024-12085 edited at 14 Jan 2025 21:29:18
Remote
- Unknown
+ Remote
Type
- Unknown
+ Information disclosure
CVE-2024-12085 edited at 14 Jan 2025 21:29:03
Severity
- Unknown
+ High
Description
+ A flaw was found in the rsync daemon which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.
References
Notes
+ This vulnerability is rated as having high severity as it helps bypass Address Space Layout Randomization (ASLR).
CVE-2024-12085 created at 14 Jan 2025 21:17:14