Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Debian 11: Advisory DLA-4015-1: rsync Updates for Critical Security Flaws

debian lts
Calendar Grey January 14, 2025
Dist Debian Esm H88
Debian LTS Advisory DLA-4020-1 outlines essential OpenSSL upgrades resolving various security weaknesses to bolster system integrity.
Several vulnerabilities were discovered in rsync, a fast, versatile, remote (and local) file-copying tool

Summary

Several vulnerabilities were discovered in rsync, a fast, versatile,
remote (and local) file-copying tool.

CVE-2024-12085

Simon Scannell, Pedro Gallegos and Jasiel Spelman reported a flaw in
the way rsync compares file checksums, allowing a remote attacker to
trigger an information leak.

CVE-2024-12086

Simon Scannell, Pedro Gallegos and Jasiel Spelman discovered a flaw
which would result in a server leaking contents of an arbitrary file
from the client's machine.

CVE-2024-12087

Simon Scannell, Pedro Gallegos and Jasiel Spelman reported a path
traversal vulnerability in the rsync daemon affecting the
--inc-recursive option, which could allow a server to write files
outside of the client's intended destination directory.

CVE-2024-12088

Simon Scannell, Pedro Gallegos and Jasiel Spelman reported that when
using the --safe-links option, rsync fails to properly verify if a
symbolic link destination contains another symbolic link with it,

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: rsync
Version: 3.2.3-4+deb11u2
CVE ID: CVE-2024-12085 CVE-2024-12086 CVE-2024-12087

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here