ELSA-2022-7793

ELSA-2022-7793 - rsync security and enhancement update

Type:SECURITY
Severity:MODERATE
Release Date:2022-11-15

Description


[3.1.3-19]
- Resolves: #2116668 - zlib: a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field

[3.1.3-18]
- Resolves: #2111175 - remote arbitrary files write inside the directories of connecting peers

[3.1.3-17]
- Related: #2043753 - New option should not be sent to the server every time

[3.1.3-16]
- Resolves: #2043753 - [RFE] Improve defaults for sparse file buffering

[3.1.3-15]
- Resolves: #2071513 - A flaw in zlib-1.2.11 when compressing (not decompressing!) certain inputs


Related CVEs


CVE-2022-37434

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 8 (aarch64) rsync-3.1.3-19.el8.src.rpmd9b92317320f10fcda87684fa54ab223-
rsync-3.1.3-19.el8.aarch64.rpmee83dd8cd155bb4ee329bbaded0e3b86-
rsync-daemon-3.1.3-19.el8.noarch.rpm6d3dafc3c04134b0fb6df1f4dd875a40-
Oracle Linux 8 (x86_64) rsync-3.1.3-19.el8.src.rpmd9b92317320f10fcda87684fa54ab223-
rsync-3.1.3-19.el8.x86_64.rpm970d98ad94067ca753c52ae0360d815b-
rsync-daemon-3.1.3-19.el8.noarch.rpm6d3dafc3c04134b0fb6df1f4dd875a40-



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete