CVE

Id
70150  
CVE No.
CVE-2014-2855  
Status
Candidate  
Description
The check_secret function in authenticate.c in rsync 3.1.0 and earlier allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a user name which does not exist in the secrets file.  
Phase
Assigned (20140415)  
Votes
None (candidate not yet proposed)  
Comments