gpp_maybe
Security update for rsync
SUSE-SLE-Micro-5.5-2025-165
This update for rsync fixes the following issues: - CVE-2024-12085: leak of uninitialized stack data on the server leading to possible ASLR bypass. (bsc#1234101) - CVE-2024-12086: leak of a client machine's file contents through the processing of checksum data. (bsc#1234102) - CVE-2024-12087: arbitrary file overwrite possible on clients when symlink syncing is enabled. (bsc#1234103) - CVE-2024-12088: bypass of the --safe-links flag may allow the placement of unsafe symlinks in a client. (bsc#1234104) - CVE-2024-12747: Fixed a race condition in rsync handling symbolic links. (bsc#1235475)
-
Release DateJan 17 2025
-
ReferencesBugzilla: 1234101, 1234102, 1234103, 1234104, 1235475, 1235895
CVEs: CVE-2024-12086, CVE-2024-12087, CVE-2024-12747, CVE-2024-12088, CVE-2024-12085 -
Typesecurity
-
Severityimportant
cloud_download Downloads
SUSE Linux Enterprise Micro 5.5 ppc64le
-
Packages
SUSE Linux Enterprise Micro 5.5 s390x
-
Packages
SUSE Linux Enterprise Micro 5.5 aarch64
-
Packages
SUSE Linux Enterprise Micro 5.5 x86_64
-
Packages