critical
Security update for rsync
SUSE-SLE-Micro-6.0-203
This update for rsync fixes the following issues: - CVE-2024-12084: Fixed Heap Buffer Overflow in Checksum Parsing (bsc#1234100). - CVE-2024-12085: Fixed Info Leak via uninitialized Stack contents defeating ASLR (bsc#1234101). - CVE-2024-12086: Fixed server leaking arbitrary client files (bsc#1234102). - CVE-2024-12087: Fixed server use of symbolic links to make client write files outside of destination directory (bsc#1234103). - CVE-2024-12088: Fixed --safe-links bypass (bsc#1234104). - CVE-2024-12747: Fixed Race Condition in rsync Handling Symbolic Links (bsc#1235475).
-
Release DateFeb 4 2025
-
ReferencesBugzilla: 1234100, 1234101, 1234102, 1234103, 1234104, 1235475
CVEs: CVE-2024-12084, CVE-2024-12085, CVE-2024-12086, CVE-2024-12087, CVE-2024-12088, CVE-2024-12747 -
Typesecurity
-
Severitycritical
cloud_download Downloads
SUSE Linux Micro 6.0 aarch64
-
Packages
SUSE Linux Micro 6.0 x86_64
-
Packages
SUSE Linux Micro 6.0 s390x
-
Packages