ELSA-2022-8291

ELSA-2022-8291 - rsync security and bug fix update

Type:SECURITY
Severity:MODERATE
Release Date:2022-11-22

Description


[3.2.3-18]
- Resolves: #2111177 - remote arbitrary files write inside the directories of connecting peers

[3.2.3-17]
- Resolves: #2116669 - zlib: a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field

[3.2.3-16]
- Related: #2081296 - Adding ci.fmf for separation of testing results

[3.2.3-15]
- Related: #2081296 - Disabling STI

[3.2.3-14]
- Resolves: #2071514 - A flaw found in zlib when compressing (not decompressing) certain inputs

[3.2.3-13]
- Resolves: #2079639 - rsync --atimes doesnt work

[3.2.3-12]
- Resolves: #2081296 - Enable fmf tests in centos stream

[3.2.3-11]
- Resolves: #2053198 - rsync segmentation fault

[3.2.3-10]
- Resolves: #2077431 - Read-only files that have changed xattrs fail to allow xattr changes


Related CVEs


CVE-2022-37434

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 9 (aarch64) rsync-3.2.3-18.el9.src.rpm3dca6d51ad33841f2cc40cc7abac3940-
rsync-3.2.3-18.el9.aarch64.rpm8578aa0169904630ea8eb887fcc47c75-
rsync-daemon-3.2.3-18.el9.noarch.rpmbf317159f2b2d48f7383f591d86d393a-
Oracle Linux 9 (x86_64) rsync-3.2.3-18.el9.src.rpm3dca6d51ad33841f2cc40cc7abac3940-
rsync-3.2.3-18.el9.x86_64.rpmc020534b8530519f188ebd8a6885e12c-
rsync-daemon-3.2.3-18.el9.noarch.rpmbf317159f2b2d48f7383f591d86d393a-



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete