librsync before 1.0.0 uses a truncated MD4 checksum to match blocks, which makes it easier for remote attackers to modify transmitted data via a birthday attack.
References
Configurations
History
No history.
Information
Published : 2015-10-26 17:59
Updated : 2020-05-19 19:55
NVD link : CVE-2014-8242
Mitre link : CVE-2014-8242
CVE.ORG link : CVE-2014-8242
JSON object : View
Products Affected
librsync_project
- librsync
CWE
CWE-310
Cryptographic Issues