New Debian rsync 3.2.7-1+deb12u2A~5.2.0.202501301650 fixes: This update addresses the following issues: * rsync: Heap Buffer Overflow in Rsync due to Improper Checksum Length Handling (CVE-2024-12084) * rsync: Info Leak via Uninitialized Stack Contents (CVE-2024-12085) * rsync: rsync server leaks arbitrary client files (CVE-2024-12086) * rsync: Path traversal vulnerability in rsync (CVE-2024-12087) * rsync: --safe-links option bypass leads to path traversal (CVE-2024-12088) * rsync: Race Condition in rsync Handling Symbolic Links (CVE-2024-12747)
--- mirror/ftp/pool/main/r/rsync/rsync_3.2.7-1A~5.2.0.202303151139.dsc +++ apt/ucs_5.2-0-errata5.2-0/source/rsync_3.2.7-1+deb12u2A~5.2.0.202501302329.dsc @@ -1,7 +1,32 @@ -3.2.7-1A~5.2.0.202303151139 [Wed, 15 Mar 2023 11:39:42 +0100] Univention builddaemon <buildd@univention.de>: +3.2.7-1+deb12u2A~5.2.0.202501302329 [Thu, 30 Jan 2025 23:29:22 -0000] Univention builddaemon <buildd@univention.de>: * UCS auto build. The following patches have been applied to the original source package - 01_dirs_update_option + 01_dirs_update_option.quilt + +3.2.7-1+deb12u2 [Wed, 15 Jan 2025 18:47:12 +0000] Samuel Henrique <samueloph@debian.org>: + + [ Salvatore Bonaccorso ] + * Fix FLAG_GOT_DIR_FLIST collission with FLAG_HLINKED + (Closes: #1093089, #1093052) + + [ Samuel Henrique ] + * d/p/Fix_use-after-free_in_generator: New patch to fix UAF + +3.2.7-1+deb12u1 [Wed, 18 Dec 2024 17:11:25 +0100] Salvatore Bonaccorso <carnil@debian.org>: + + * Non-maintainer upload by the Security Team. + * Some checksum buffer fixes. (CVE-2024-12084) + * Another cast when multiplying integers. (CVE-2024-12084) + * prevent information leak off the stack (CVE-2024-12085) + * refuse fuzzy options when fuzzy not selected (CVE-2024-12086) + * added secure_relative_open() (CVE-2024-12086) + * receiver: use secure_relative_open() for basis file (CVE-2024-12086) + * disallow ../ elements in relpath for secure_relative_open (CVE-2024-12086) + * Refuse a duplicate dirlist. (CVE-2024-12087) + * range check dir_ndx before use (CVE-2024-12087) + * make --safe-links stricter (CVE-2024-12088) + * fixed symlink race condition in sender (CVE-2024-12747) + * raise protocol version to 32 3.2.7-1 [Sun, 18 Dec 2022 14:10:54 +0000] Samuel Henrique <samueloph@debian.org>: <http://piuparts.knut.univention.de/5.2-0/#8395963614892235703>
OK: bug OK: yaml OK: announce_errata OK: patch OK: piuparts [5.2-0] c400582090 Bug #57932: rsync advisory doc/errata/staging/rsync.yaml | 23 +++++++++++++++++++++++ 1 file changed, 23 insertions(+)
<https://errata.software-univention.de/#/?erratum=5.2x18>