Login
Newsletter
Werbung

Sicherheit: Schreiben von Dateien außerhalb des Zielverzeichnisses in rsync (Fedora Core 2)
Aktuelle Meldungen Distributionen
Name: Schreiben von Dateien außerhalb des Zielverzeichnisses in rsync (Fedora Core 2)
ID: FEDORA-2004-269
Distribution: Fedora
Plattformen: Fedora Core 2
Datum: Fr, 20. August 2004, 13:00
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0792
Applikationen: rsync

Originalnachricht

---------------------------------------------------------------------
Fedora Update Notification
FEDORA-2004-269
2004-08-19
---------------------------------------------------------------------

Product : Fedora Core 2
Name : rsync
Version : 2.6.2
Release : 1.fc2.0
Summary : A program for synchronizing files over a network.
Description :
Rsync uses a reliable algorithm to bring remote and host files into
sync very quickly. Rsync is fast because it just sends the differences
in the files over the network instead of sending the complete
files. Rsync is often used as a very powerful mirroring process or
just as a more capable replacement for the rcp command. A technical
report which describes the rsync algorithm is included in this
package.

---------------------------------------------------------------------
Update Information:

This update backports a security fix to a path-sanitizing flaw that
affects rsync when it is used in daemon mode without also using
chroot.

For more information see http://samba.org/rsync/#security_aug04

---------------------------------------------------------------------
* Thu Aug 19 2004 Jay Fenlason <fenlason@redhat.com> 2.6.2-1.fc2.0

- Backport fix for CAN-2004-0792


---------------------------------------------------------------------
This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/

d6ae9d1c6e5d18903911e1fdedd55a03 SRPMS/rsync-2.6.2-1.fc2.0.src.rpm
f03bc05659c874cb39d4bab606dfaabf x86_64/rsync-2.6.2-1.fc2.0.x86_64.rpm
97f2ed68e7b3f7e0c5888b0aa8cd2088
x86_64/debug/rsync-debuginfo-2.6.2-1.fc2.0.x86_64.rpm
1dd097feb524de781f6ae9ecf74bcc3d i386/rsync-2.6.2-1.fc2.0.i386.rpm
38590683c5bca0a599fbc70a971c6b7e
i386/debug/rsync-debuginfo-2.6.2-1.fc2.0.i386.rpm

This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.
---------------------------------------------------------------------


--
fedora-announce-list mailing list
fedora-announce-list@redhat.com
http://www.redhat.com/mailman/listinfo/fedora-announce-list
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung