Login
Newsletter
Werbung

Sicherheit: Schreiben von Dateien außerhalb des Zielverzeichnisses in rsync (Fedora Core 1)
Aktuelle Meldungen Distributionen
Name: Schreiben von Dateien außerhalb des Zielverzeichnisses in rsync (Fedora Core 1)
ID: FEDORA-2004-268
Distribution: Fedora
Plattformen: Fedora Core 1
Datum: Sa, 21. August 2004, 13:00
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0792
Applikationen: rsync

Originalnachricht

---------------------------------------------------------------------
Fedora Update Notification
FEDORA-2004-268
2004-08-19
---------------------------------------------------------------------

Product : Fedora Core 1
Name : rsync
Version : 2.5.7
Release : 5.fc1.1
Summary : A program for synchronizing files over a network.
Description :
Rsync uses a reliable algorithm to bring remote and host files into
sync very quickly. Rsync is fast because it just sends the differences
in the files over the network instead of sending the complete
files. Rsync is often used as a very powerful mirroring process or
just as a more capable replacement for the rcp command. A technical
report which describes the rsync algorithm is included in this
package.

---------------------------------------------------------------------
Update Information:

This update backports a security fix to a path-sanitizing flaw that
affects rsync when it is used in daemon mode without also using
chroot.

For more information see http://samba.org/rsync/#security_aug04

---------------------------------------------------------------------
* Thu Aug 19 2004 Jay Fenlason <fenlason@redhat.com> 2.5.7-5.fc1.1

- Backport fix for CAN-2004-0792


---------------------------------------------------------------------
This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/

01fb9ef513ef0d484efb1bd66e91ad69 SRPMS/rsync-2.5.7-5.fc1.1.src.rpm
dd13aba3dc99efc30ecaa0eeb49f242e x86_64/rsync-2.5.7-5.fc1.1.x86_64.rpm
d8963193e902465e632e0ed993e92f82
x86_64/debug/rsync-debuginfo-2.5.7-5.fc1.1.x86_64.rpm
bab0cb276f77596a6b9520401298764f i386/rsync-2.5.7-5.fc1.1.i386.rpm
094fa40ae453fddd43edce9fd10a054b
i386/debug/rsync-debuginfo-2.5.7-5.fc1.1.i386.rpm

This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.
---------------------------------------------------------------------


--
fedora-announce-list mailing list
fedora-announce-list@redhat.com
http://www.redhat.com/mailman/listinfo/fedora-announce-list
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung