From: Mikle Kolyada Date: Wed, 17 Jan 2018 02:21:26 +0000 (+0300) Subject: Add GLSA 201801-16 X-Git-Url: http://git.tremily.us/?a=commitdiff_plain;h=b90a90bed2629830e2ae17fee9d100637b3fce81;p=gentoo.git Add GLSA 201801-16 --- diff --git a/glsa-201801-16.xml b/glsa-201801-16.xml new file mode 100644 index 000000000000..200f2586ae10 --- /dev/null +++ b/glsa-201801-16.xml @@ -0,0 +1,52 @@ + + + + rsync: Multiple vulnerabilities + Multiple vulnerabilities have been found in rsync, the worst of + which could allow remote attackers to bypass access restrictions. + + rsync + 2018-01-17 + 2018-01-17 + 636714 + 640570 + remote + + + 3.1.2-r2 + 3.1.2-r2 + + + +

File transfer program to keep remote files into sync.

+
+ +

Multiple vulnerabilities have been discovered in rsync. Please review + the CVE identifiers referenced below for details. +

+
+ +

A remote attacker could bypass intended access restrictions or cause a + Denial of Service condition. +

+
+ +

There is no known workaround at this time.

+
+ +

All rsync users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=net-misc/rsync-3.1.2-r2" + + +
+ + CVE-2017-16548 + CVE-2017-17433 + CVE-2017-17434 + + whissi + whissi +