Accepted: rsync 2.6.9-5.1ubuntu1 (source)
Michael Vogt
michael.vogt at ubuntu.com
Thu Dec 6 11:40:18 GMT 2007
Accepted:
OK: rsync_2.6.9.orig.tar.gz
OK: rsync_2.6.9-5.1ubuntu1.diff.gz
OK: rsync_2.6.9-5.1ubuntu1.dsc
-> Component: main Section: net
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Thu, 06 Dec 2007 12:34:46 +0100
Source: rsync
Binary: rsync
Architecture: source
Version: 2.6.9-5.1ubuntu1
Distribution: hardy
Urgency: high
Maintainer: Ubuntu Core Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Michael Vogt <michael.vogt at ubuntu.com>
Description:
rsync - fast remote file copy program (like rcp)
Closes: 453652
Changes:
rsync (2.6.9-5.1ubuntu1) hardy; urgency=low
.
* Merge from debian unstable, remaining changes:
- Remove stop links from rc0 and rc6
(and use update-rc.d multiuser instead of defaults)
- maintainer field changed
- depend on sysv-rc
.
rsync (2.6.9-5.1) unstable; urgency=high
.
* Non-maintainer upload by testing-security team.
* This update addresses the following security issues (Closes: #453652):
- When "use chroot" option is disabled, a programming error
can be exploited by a user to trick rsync into creating a
symlink that points outside the module's hierarchy.
- A programming error within the "exclude", "exclude from" and "filter"
options can be exploited via a symlink attack to gain access
to hidden files if the filename is known.
Files:
9b23f2f3139523ea5eab63ea44a0e04c 658 net optional rsync_2.6.9-5.1ubuntu1.dsc
bd2651b86df3739efa2e03ee4d31cd8f 43801 net optional rsync_2.6.9-5.1ubuntu1.diff.gz
Original-Maintainer: Paul Slootman <paul at debian.org>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iD8DBQFHV99IliSD4VZixzQRAk6YAJsEagQuD+1scWMWZwjzcEuNZ1kbLQCeNH6a
vGhN2NncO5ltu3D7kGoPQIY=
=1use
-----END PGP SIGNATURE-----
More information about the Hardy-changes
mailing list