Goverp Advocate
Joined: 07 Mar 2007 Posts: 2201
|
Posted: Sat Jan 25, 2025 9:50 am Post subject: rsync vulnerabilities |
|
|
There's been a flurry of interest in a batch of vulnerabilities in rsyncd. Release 3.4.0 is supposed to contain the fixes, so after my "emerge --update --..." today I thought I'd check, and found it was still at net-misc/rsync-3.3.0-r2, so I got all worked up. However, a dig on bugs.gentoo.org turns up bug 948106, which shows the fixes are in that "-r2", so all is well.
The bug report is interesting reading. Kudos to the Gentoo devs for taking it carefully, rather than just pumping 3.4.0 out (as at least one other distro has already done). _________________ Greybeard |
|