From b90a90bed2629830e2ae17fee9d100637b3fce81 Mon Sep 17 00:00:00 2001 From: Mikle Kolyada Date: Wed, 17 Jan 2018 05:21:26 +0300 Subject: [PATCH] Add GLSA 201801-16 --- glsa-201801-16.xml | 52 ++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 52 insertions(+) create mode 100644 glsa-201801-16.xml diff --git a/glsa-201801-16.xml b/glsa-201801-16.xml new file mode 100644 index 000000000000..200f2586ae10 --- /dev/null +++ b/glsa-201801-16.xml @@ -0,0 +1,52 @@ + + + + rsync: Multiple vulnerabilities + Multiple vulnerabilities have been found in rsync, the worst of + which could allow remote attackers to bypass access restrictions. + + rsync + 2018-01-17 + 2018-01-17 + 636714 + 640570 + remote + + + 3.1.2-r2 + 3.1.2-r2 + + + +

File transfer program to keep remote files into sync.

+
+ +

Multiple vulnerabilities have been discovered in rsync. Please review + the CVE identifiers referenced below for details. +

+
+ +

A remote attacker could bypass intended access restrictions or cause a + Denial of Service condition. +

+
+ +

There is no known workaround at this time.

+
+ +

All rsync users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=net-misc/rsync-3.1.2-r2" + + +
+ + CVE-2017-16548 + CVE-2017-17433 + CVE-2017-17434 + + whissi + whissi +
-- 2.26.2