critical
Security update for rsync
SUSE-SLE-Micro-6.1-15
This update for rsync fixes the following issues: - Bump protocol version to 32 - make it easier to show server is patched. - Fix FLAG_GOT_DIR_FLIST collission with FLAG_HLINKED - Security update,CVE-2024-12747, bsc#1235475 race condition in handling symbolic links - Security update, fix multiple vulnerabilities: * CVE-2024-12084, bsc#1234100 - Heap Buffer Overflow in Checksum Parsing * CVE-2024-12085, bsc#1234101 - Info Leak via uninitialized Stack contents defeats ASLR * CVE-2024-12086, bsc#1234102 - Server leaks arbitrary client files * CVE-2024-12087, bsc#1234103 - Server can make client write files outside of destination directory using symbolic links * CVE-2024-12088, bsc#1234104 - --safe-links Bypass
-
Release DateFeb 7 2025
-
ReferencesBugzilla: 1234100, 1234101, 1234102, 1234103, 1234104, 1235475
CVEs: CVE-2024-12084, CVE-2024-12085, CVE-2024-12086, CVE-2024-12087, CVE-2024-12088, CVE-2024-12747 -
Typesecurity
-
Severitycritical
cloud_download Downloads
SUSE Linux Micro 6.1 ppc64le
-
Packages
SUSE Linux Micro 6.1 s390x
-
Packages
SUSE Linux Micro 6.1 aarch64
-
Packages
SUSE Linux Micro 6.1 x86_64
-
Packages