Hi AIX OpenSource-Team,
please update rsync, because of various security issues:
AIX-Toolbox:
3.3.0
AFFECTED VERSIONS:
rsync < 3.4.0
-
CVE-2024-12084 - Heap Buffer Overflow in Checksum Parsing.
-
CVE-2024-12085 - Info Leak via uninitialized Stack contents defeats ASLR.
-
CVE-2024-12086 - Server leaks arbitrary client files.
-
CVE-2024-12087 - Server can make client write files outside of destination directory using symbolic links.
-
CVE-2024-12088 - --safe-links Bypass.
-
CVE-2024-12747 - symlink race condition.
https://download.samba.org/pub/rsync/NEWS#3.4.0
------------------------------
Tobias Schröer
------------------------------