librsync before 1.0.0 uses a truncated MD4 checksum to match blocks, which makes it easier for remote attackers to modify transmitted data via a birthday attack.
References
Configurations
Information
Published : 2015-10-26 10:59
Updated : 2020-05-19 12:55
NVD link : CVE-2014-8242
Mitre link : CVE-2014-8242
JSON object : View
CWE
CWE-310
Cryptographic Issues
Products Affected
librsync_project
- librsync